What is Rapid7 Nexpose Warehouse? #
Rapid7 Nexpose Warehouse is a dimensional database that stores assessment data and reports from InsightVM in an on-premises PostgreSQL database.
Why Should You Use the Rapid7 Nexpose Warehouse Connector? #
The Rapid7 Nexpose Warehouse connector provides visibility into assets and vulnerability information in your environment. You can use this visibility to:
-
ensure assets are managed per your security policies
-
derive relationships between assets, users, and data
How Does This Connector Work? #
Lucidum executes read-only requests to the Rapid7 Nexpose Warehouse REST API and ingests only meta-data about Rapid7 Nexpose Warehouse assets. Lucidum does not retrieve any data stored on Nexpose Warehouse.
Configuring the Connector in Lucidum #
Field |
Description |
Example |
---|---|---|
Host |
The hostname or IP address of the Postgres SQL server used by Nexpose. |
|
Port |
Port for the Postgres SQL server used by Nexpose. Default value is 5432 |
5432 |
Database |
Name of the database used by Nexpose. |
|
Username |
User name for an account on the Postgres SQL server used by Nexpose. |
|
Password |
User name for an account on the Postgres SQL server used by Nexpose. |
|
Source Documentation #
Creating Credentials #
-
In Insight Platform, create a user account. For details, see:Â https://docs.rapid7.com/insight/rbac/#add-users
-
In Insight VM, assign the user account the role User, ensuring the role includes the permissions View Site Asset Data, View Group Asset Data, and View Vulnerability Investigations . For details, see: https://docs.rapid7.com/insightvm/managing-users-and-authentication#permissions-tables and https://docs.rapid7.com/insightvm/managing-users-and-authentication#user
-
In Insight Platform, login as that user and generate an API Key. For details, see https://docs.rapid7.com/insight/managing-platform-api-keys/#generating-a-user-key
Required Permissions #
Object |
Permissions |
---|---|
Role |
Users |
InsightVM Permissions |
View Site Asset Data View Group Asset Data View Vulnerability Investigation |
API Documentation #
https://help.rapid7.com/insightvm/en-us/api/index.html