InsightIDR – Missing SentinelOne and CrowdStrike Alerts for some MDR customers

Incident Report for Rapid7

Resolved

Delayed alerts for SentinelOne and CrowdStrike for MDR customers have now been resolved. Replay of the delayed alerts is now complete. The MDR SOC will reach out via standard methods if investigation reveals any alerts requiring customer awareness or response.
Posted Jul 29, 2025 - 06:28 UTC

Identified

The issue affecting alerts for SentinelOne and CrowdStrike for MDR customers has now been mitigated. Work is ongoing to replay missed alerts for MDR SOC analyst triage and investigation.
Posted Jul 29, 2025 - 05:44 UTC

Investigating

We have identified an issue that began on July 24, 2025, at 17:21 UTC, where High and Critical alerts from SentinelOne and CrowdStrike are not populating correctly in InsightIDR for a subset of MDR customers who have opted to have the Rapid7 SOC monitor third-party alerts from these event sources.
Posted Jul 29, 2025 - 03:59 UTC
This incident affected: InsightIDR (US1) (Event Processing), InsightIDR (EU) (Event Processing), InsightIDR (CA) (Event Processing), InsightIDR (AU) (Event Processing), InsightIDR (AP) (Event Processing), InsightIDR (US2) (Event Processing), and InsightIDR (US3) (Event Processing).