Hi folks,
I'm having an issue with the Rapid7 Insight Platform Vulnerability Management Reports (via Codeless Connector Framework) data connector in Microsoft Sentinel and hoping someone here has hit this before.
The Setup:
-
Installed and configured the connector via Content Hub using the Codeless Connector Framework (CCF).
-
Verified API credentials, correct region, and associated Data Collection Rule (DCR).
The Issue:
-
The first run worked - initial vulnerability and asset logs successfully pulled into the Sentinel tables.
-
Immediately after that initial sync, all ingestion stopped.
-
It has been sitting for over 7 days now. The connector status still shows as Connected, but the Last Log Received timestamp is permanently frozen at the initial setup time. No new data is flowing into the tables.
What I've Checked:
-
Verified the DCR configuration and stream mappings.
-
Reviewed MS documentation, but guidance for troubleshooting this specific CCF connector is super minimal.
Has anyone run into this behavior with CCF connectors? Could this be a polling interval/state tracking bug in the backend, API pagination/rate-limiting issue on Rapid7's end, or a missing configuration step not in the docs?
Appreciate any insights or troubleshooting tips!