Hi all,
We currently have the Rapid7 InsightIDR to Microsoft 365 workflow set up via InsightConnect, and it is successfully sending email notifications when an Investigation is created.
However, we’ve noticed that it does not appear to trigger for:
- Standard Alerts
- Managed Alerts (MDR)
At the moment, only Investigations generate the email output.
The workflow does work great and ticks alot of boxes for us as it pretty much spits out the full log onto an email which we pipe into our service desk, saves a bit of time when triaging. Would be good if we can also expand this to standard alerts and MDR alerts.
The guidance in the setup states “Make sure Alerts is selected under "Data Export Types" and click "Save" however, I don’t seem to have that option in IDR.
Just wondering if anyone has managed to overcome this or whether you have any advice?
Thanks!
