Forward the downpipes audit trail to Rapid7 InsightIDR
Rapid7 InsightIDR receives the downpipes audit trail through a Custom Logs webhook or a Generic API log source. The engine dials out to that URL on the scheduler tick and posts the audit events as a JSON array.
InsightIDR has no HTTP Event Collector, so the Splunk HEC shape would arrive as unparsed text. This vendor’s tile has no format picker and sends a JSON array; if your log source would rather read newline-delimited JSON, set the push up from Custom endpoint, which is the one tile that leaves the wire to you. Either way you authenticate with the value the log source issues, sent in the Authorization header. Set up a custom-log parser on the InsightIDR side so the fields become queryable.
Because the engine makes the outbound call, a Cloudflare Access perimeter on your console hostname never blocks this: there is no inbound request for Access to turn away.
What you need
- An InsightIDR role that can add a Custom Logs or Generic API log source.
- The log source URL and its auth value, and owner access to the downpipes console.
Set it up
- In InsightIDR, add a log source: either a Custom Logs source with a webhook or HTTP collector, or a Generic API log source. Note its URL and the auth it issues (a Basic credential, or a bearer value in
Authorization). - In the downpipes console, open Integrations, choose this vendor’s tile, and set up the SIEM audit push there (owner-only, asks for a fresh step-up sign-in).
- This tile fixes Delivery to HTTP endpoint and Format to JSON array, with no picker to set either. Paste the InsightIDR log source URL into Endpoint URL.
- Set Auth header name to match the source. For a bearer, leave it as
Authorizationand pasteBearer <token>as the Auth secret; for Basic, keepAuthorizationand pasteBasic <base64>. - Leave Enabled ticked to start draining on the next scheduler tick after you save, or clear it to test before any real event leaves. Choose Configure to save.
- Choose Test send and confirm InsightIDR accepts it. A test send works whether the destination is enabled or not, and never advances the delivery cursor. If you cleared Enabled, choose Enable now.
What lands in Rapid7 InsightIDR
Each batch arrives as a JSON array of raw audit events:
[{"seq":4097,"ts":"2026-06-19T02:14:08.221Z","actorEmail":"ops@acme.example","action":"restore-approve","outcome":"success","...":"..."}]
Map the fields you want to InsightIDR’s custom-log parsing so action, outcome and actorEmail are queryable. The ts field is the event time.
Good to know
- There is no HEC on InsightIDR, so send generic JSON. The Splunk HEC format would arrive as unparsed text. This tile’s JSON array suits a Custom Logs or Generic API source; NDJSON is the alternative, and you choose it on the Custom endpoint tile.
- Delivery is at-least-once, not exactly-once. Every event carries a stable
seqandhashto dedup on. The feed carries operator identity (member emails, source IPs, roles and approver emails); no backup data and no secret values. For the shared push mechanics and the pull alternative, see forwarding the audit log to your SIEM.
Last updated .