There are two ways to install the dashboard - via the Splunk app listing, or manually with a provided dashboard
package. To install the dashboard via the app listing, follow these steps:
Apps
menu in Splunk, select Manage Apps
Browse More Apps
Install
from the app listingTo install the add-on manually, follow these steps:
Apps
menu in Splunk, select Manage Apps
Install app from file
The add-on should now appear as Rapid7 InsightVM Dashboard
under the Apps menu in Splunk.
This dashboard must be used alongside the Rapid7 InsightVM Technology Add-On. The add-on serves as the method for
retrieving asset and vulnerability data, which is then visualized with this dashboard. There are three sourcetypes to
keep in mind when searching or creating visualizations of this data:
There are a few different components in the Asset Dashboard that display or visualize the imported InsightVM asset
data. It's important to ensure that the correct index is selected here, as otherwise you may not see any data. The
default index for the Dashboard follows that of the Technology Add-On and will be set to rapid7
, but you can update
this if a different one was chosen for data import.
Additional filtering can be done with the Tags
dropdown, which uses tags - aggregates of site, asset groups, and
asset tags - retrieved from InsightVM, and the Time Period
dropdown, which allows you to select a date range for
your data.
Field | Description |
---|---|
Total Assets Scanned | The total number scanned across imported assets |
Total Asset Riskscore | The total risk score across imported assets |
Average Asset Riskscore | The average risk score across imported assets |
Most Common Operating Systems | A chart showing a breakdown of operating systems in the environment |
Most Vulnerable Hosts | A table listing most vulnerable hosts based on risk score |
There are a few different components in the Vulnerability Dashboard that display or visualize the imported InsightVM
vulnerability data. It's important to ensure that the correct index is selected here, as otherwise you may not see
any data.
Additional filtering can be done with the Time Period
dropdown, which allows you to select a date range for your
data.
Field | Description |
---|---|
New Vulnerability Findings | A count of new vulnerability findings based on the latest import of InsightVM data |
Remediated Vulnerability Findings | A count of remediated vulnerability findings based on the latest import of InsightVM data |
Active Vulnerabilities by Solution Type | A chart showing a breakdown of solutions available for active vulnerabilities |
Top Vulnerability Occurrences | A table listing the most frequently occurring vulnerabilities across assets |
Top Solutions by Asset Count | A table listing the top solutions based on their applicability across assets |
Added Host Not scanned in the last 30 days & Asset Management dashboards.
1.0.1 - Removed unnecessary index dependency
1.0.0 - Initial release of Dashboard for use with Rapid7 InsightVM Technology Add-On
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.