T Techclick ← All lessons
Rapid7 · Evidence desk · Interactive lesson

Prove Rapid7 is seeing this asset — first tool + proof field

01:40. Slack: “Is the collector seeing this asset? Why no detection?” The CIO is already in the channel. A screenshot of the InsightIDR dashboard is not proof. This desk is five official surfaces — asset, collector health, investigation / detection, last scan, vulnerability — each mapped to one ticket, one first click, and one field you paste before you quarantine, Scan Now, or flip a Rule Action.

~20 min read · L2 primary · Quiz at end · Blog 1 · Factory

⚡ Quick Answer

How you prove Rapid7 is seeing this asset: InsightVM / InsightIDR asset, collector health, investigation / detection, last scan, vulnerability. Five tickets with first tool and one proof field.

After this page you can

Quick answer (say this out loud)

Assets / Asset Details answers “is this host even in Rapid7?” Data Collection Health → Collectors answers “is the collector Active, and is this event source Running with incoming data?” Investigations + Detection Rule Library answers “did a rule fire — and is Rule Action Creates Investigations, Tracks Notable Events, or Off?” Last Scan / Last Scan Time answers “when was this asset last assessed by a scan engine or by the Insight Agent?” Vulnerabilities answers “is this finding real — First Found, risk, exception?” A green dashboard tile is not an asset record. An empty investigation queue is not a dead platform.

1. Why “is Rapid7 seeing it?” is five questions

Operators collapse five failures into one sentence. The laptop was never an assessed asset. The Pune collector went Inactive. The detection rule’s Rule Action is Off (or an exception swallowed the user). The site Last Scan is a discovery ping from last month. The CVE is First Found on a different host, or already excepted. Those are five first clicks.

This page is the night-shift desk for proof. The factory taught the product pick — InsightVM is weakness, InsightIDR is behavior, same host is a pivot. Here you learn the five tools you actually open, in order, when someone asks you to prove Rapid7 is seeing this asset — or to explain why there is no detection.

Hero · five tiles, one missing host
Night-shift operations desk with five glowing proof tiles for asset, collector, investigation, last scan, and vulnerability
Notice: five tiles, not one “Rapid7 dashboard.” You pick the tile that matches the question, then you quote one field.
Interview line

If they say “prove Rapid7 is seeing this asset,” do not say “I opened InsightIDR.” Say: “I prove the host on Assets / Asset Details, the pipe with Data Collection Health Collectors Active/Inactive plus event-source Running and incoming data, the detection with Investigations Status + Detection Rule + Rule Action, the assessment with Last Scan versus Last Scan Time, and the finding with First Found + risk + exception.”

2. Mental model — five proof tools

Memorise five named objects before you click. Each tool is allowed to prove one thing. Over-claiming a field is how you quarantine a box that was never in inventory, or flip a Rule Action because Log Search was empty for the wrong hour.

1 · Asset

InsightVM Assets (Assessed / Unassessed). InsightIDR Asset Details (global search). Proves hostname, IP, site, OS, agent present. Does not prove a collector is up or a CVE is First Found.

2 · Collector health

Data Collection → Data Collection Health → Collectors. Proves the on-prem pipe: Active / Inactive, hostname, IP, CPU / memory. Event Sources tab: Running + Monitor Health incoming vs parsed. Does not prove a Rule Action.

3 · Investigation / detection

Investigations + Detection Rules → Detection Rule Library. Proves Status, Priority, Detection Rule, Rule Action (Creates Investigations / Creates Alert / Tracks Notable Events / Assess Activity / Off), Exceptions. Empty queue is data.

4 · Last scan

Site / Assets Last Scan = last discovery, vulnerability, or policy scan. Query Builder Last Scan Time = last Insight Agent assessment. Asset Details Last On Demand Agent Scan. Completed ≠ authenticated.

5 · Vulnerability

Security Console Vulnerabilities / asset listing. Proves First Found, risk score, CVSS, Severity, Instances, exception (reason + expiry). A weekly PDF tile is not a finding.

Hard words, once

Collector ≠ Insight Agent ≠ Scan Engine. Assessed = scanned or agent-installed. Last ScanLast Scan Time. Rule Action Off = no investigation by design. First Found = first detect in the environment.

Flow 1 · five tools, one question each
Write host + IP + UTC first · then pick the tool Is Rapid7 seeing this? five questions, not one Asset In inventory? name · IP · site Assets / Asset Details Assessed vs Unassessed not a CVE verdict Collector health Pipe alive? Active / Inactive Running · incoming Data Collection Health not a Rule Action Investigation Did a rule fire? Status · Detection Rule Rule Action · Exception Investigations · Library not a Last Scan Last scan When assessed? Last Scan Last Scan Time Sites · Query Builder completed ≠ authed Vulnerability This finding? First Found risk · exception Vulnerabilities icon not a collector up Empty Investigations is data. It usually means the asset, the collector, or Rule Action never landed. Do not invent a quarantine from an empty queue. Start at Assets or Data Collection Health.

Read left → right. Each box is allowed one claim. If you cannot name the field, you are not proving — you are guessing.

Say this out loud

I prove the asset, then the collector, then the investigation / Rule Action, then the last scan, then the vulnerability. I do not Quarantine Asset, Scan Now a VLAN, or flip a detection rule until I can quote the field that made me do it.

3. Decision flow — ticket → first tool

Flowchart first. Do not open Take Action → Quarantine Asset, and do not click Scan Now, until a diamond says so.

Path · pick the branch before the menu
Abstract diamond splitting into five Rapid7 proof paths with one amber break
Notice: the diamond is the ticket. The path is the tool. The field comes last. Do not reverse that order.
Flow 2 · first-tool diamond
Symptom first · tool second · field third What must we prove? Host in Rapid7? or already inside? Host missing Assets / Asset Details name · IP · Assessed No logs / no IDR Collectors + Event Sources Active · Running · incoming Why no detection? Investigations · Library Status · Rule Action Stale / never scanned Last Scan / Last Scan Time engine vs agent This CVE / isolate Vulnerabilities First Found · exception No asset record → stop. There is no investigation to hunt and no First Found to quote. Add the IP to a site (or install the Insight Agent), then re-open Assets. Do not Quarantine a missing host. Diamond = decision. Do not Scan Now or Quarantine from the bottom box. Official: Collector Shows as Inactive. Event source Running ≠ data in Log Search. Last Scan ≠ Last Scan Time.

Read the diamond first. A missing host never starts in Detection Rules. “Why no detection?” never starts in Vulnerabilities. A stale Last Scan never starts in Quarantine Asset.

4. How to choose — first tool + proof field

Print this next to the InsightIDR and Security Console tabs. If you cannot recite the proof field, you are not ready to change anything.

If the ticket says…First tool (official path)Proof fieldDo not open first
Laptop / new VM / “is Rapid7 even seeing this host?” InsightVM Assets (Assessed / Unassessed / Discovered). InsightIDR global search → Asset Details Hostname + IP + site + Assessed vs Unassessed (or agent present on Asset Details) Quarantine Asset / Detection Rule Library
Whole site silent / “collector not seeing this asset” / Log Search empty SIEM (InsightIDR) Data Collection → Data Collection Health → Collectors, then Event Sources Monitor Health Collector Active / Inactive + event source Running + incoming vs parsed (and any orange/red error) A new URL-style Allow, or flipping Rule Action Off
“Why no detection?” / PowerShell seen on the box, queue is empty Investigations (filter Detection Rule + asset) then Detection Rules → Detection Rule Library Investigation Status + Detection Rule + Rule Action + Exceptions tab Scan Now of the VLAN / VM exception
“When did we last assess this?” / weekly PDF looks thin Site detail / Assets Last Scan. Query Builder Last Scan Time. Asset Details Last On Demand Agent Scan Last Scan (engine: discovery / vuln / policy) vs Last Scan Time (Insight Agent) Take Action → Quarantine
“Critical CVE — isolate it” / finding looks new on a freeze host Security Console Vulnerabilities → asset listing First Found + risk score + Severity + whether an exception already exists (reason + expiry) InsightIDR Rule Action change
Official Last Scan caveat

Rapid7 documents two different clocks. Last Scan on the Sites detail page or Assets is the last time a discovery, vulnerability, or policy scan was run. Last Scan Time in Query Builder is the last time the asset was assessed by the Rapid7 Agent (Insight Agent). Quoting the wrong column is how you tell a change board “we scanned yesterday” when only an agent heartbeat moved.

5. Runbook Side A → B → C

Side A proves the host exists and the collector pipe is alive. Side B proves why a detection did or did not become an investigation. Side C proves the last assessment and the vulnerability finding. On a messy Sev-2, do them in this order until a field lights up.

Side A — Asset, then collector (is the collector seeing this asset?)

  1. Search the asset before you argue about detections

    InsightVM: click the Assets icon. Official: Locating and working with assets. Sort / search by address, name, site, OS, last assessed. Assessed = scanned or Insight Agent installed. Unassessed / Discovered = seen by a dynamic discovery connection (LDAP, Azure, AWS) and assigned to a site, but not yet assessed for vulnerabilities or policy. InsightIDR: global search for hostname or IP → Asset Details (Assets on Your Domain). Quote hostname, IP, site. If there is no record, stop. There is no investigation and no First Found to chase.

  2. Open Data Collection Health, not Detection Rules

    Path: left menu Data Collection, or top-right Data Collection icon → Data Collection Health. Then Collectors. Official: Collector Troubleshooting — view Linux Collector details on Data Collection > Data Collection Health > Collectors. Quote hostname, IP, OS, CPU / memory when shown. Official state you care about: Collector Shows as Inactive. Restart is service collector restart (Linux, may need sudo) or the Windows Services app → Collector. Do not flip a Rule Action because the collector is dark.

  3. Prove the event source, not the dashboard tile

    Same Data Collection page → Event Sources tab. Status lives under the event source name: Running, or actions Start Running / Stop Running. Click Monitor Health. Official: incoming data (events received per minute, compressed data sent to the platform) and parsed vs unparsed. Orange warnings / red errors under the name are the ticket. Source: Monitor Event Source Health; Event Source Troubleshooting.

  4. If the card says Running and Log Search is empty, stay on the pipe

    Official unexpected case: event source appears correctly running, but no data. Causes Rapid7 names: the collector that hosts the event source is inactive; something is blocking the connection (firewall, endpoint protection, proxy); or the source is ingesting data that is not being parsed (EPM can move while Log Search has no log). Generate a test event (user, machine, exact timestamp). Non-English fields go to Unparsed Data. A test environment may be dropped on purpose. Source: Event Source Troubleshooting.

insight.rapid7.com · Data Collection → Data Collection Health → Collectors
Training mock · not live

Data Collection / Data Collection Health / Collectors

Collectors

r7-col-pune-01.lab.example
Inactive
203.0.113.41
— (details missing while Inactive)
ObjectNameStatusProof
Collectorr7-col-pune-01InactiveNo hostname / CPU while down
Event sourceDC-LAB-01 AD SecurityRunningMonitor Health: incoming 0 / min
OFFICIAL STATE:
Collector Shows as Inactive — restart Collector service, then re-read Incoming Data.
Event source Running + incoming 0 is still a pipe ticket, not a Rule Action ticket.

Source: Rapid7 Docs — Collector Troubleshooting (Data Collection > Data Collection Health > Collectors; Collector Shows as Inactive); Monitor Event Source Health; Event Source Troubleshooting (Running vs incoming). Lab identities only. Training mock · not live.

Side B — Investigation / detection (why no detection?)

  1. Open Investigations, not Vulnerabilities

    Left menu Investigations. Official filters: Date Range (default 28 days), Priority (Critical / High / Medium / Low), Status (Open, Investigating, Waiting, Closed), Detection Rule, Investigation Type (User, Detection Rule, Scheduled Endpoint Queries, Automation), Assignee. Search by investigation name, user, or asset. Expand the card for linked assets / users. If the queue is empty for that asset + rule + window, that emptiness is evidence — do not invent a quarantine.

  2. Read Status, Detection Rule, Priority, Disposition

    Open the investigation. System-created names come from the detection rule that triggered them. Quote Status, inherited Priority, Assignee, Disposition. Official dispositions: Undecided, Benign, Malicious, Unknown, Not Applicable, Security Test, False Positive. You cannot close while disposition is Undecided. Timeline icons include Alert, Notable behavior, Logs, Workflow, Endpoint queries, Notes, User, Asset, Automation workflow. Source: Investigations; Analyze an investigation.

  3. If there is no investigation, open the Detection Rule Library

    Path: Detection Rules → Detection Rule Library. Open the rule that should have fired. Official Rule Actions: Creates Investigations, Creates Alert, Tracks Notable Events, Assess Activity (7-day score, then auto Off unless you change it), Off. Off and Assess Activity are allowed to produce an empty Investigations queue. Then open the Exceptions tab — an exception-level Rule Action overrides the rule for that user / asset / IP. Quote Exception Name + exception matches. Source: Modify Detection Rules.

  4. Only then use Log Search as residual proof

    From Asset Details, Search Related Logs opens Log Search with the asset in the query bar (default last hour — widen the UTC window on the ticket). From an investigation: Explore Contextual Data → Search Logs, then Add to Investigation. Audit Logs log set holds investigation and alert updates. Empty parsed logs after a healthy collector is a parsing ticket, not a “Rapid7 is down” ticket.

insight.rapid7.com · Investigations · INV-1042 · Detection Rule Library
Training mock · not live

Investigations / INV-1042 · then Detection Rules / Detection Rule Library

Investigation details

Open
High
LAB · Encoded PowerShell
Undecided
win-l2-08.lab.example · 10.10.8.22
Creates Investigations
WHY-NO-DETECTION OUTCOME (the other ticket):
Investigations filter asset=10.10.8.22 + last 24h → 0 rows
Library: Rule Action = Off · Exceptions tab: asset is 10.10.8.22 · matches=14

Source: Rapid7 Docs — Investigations (filters, Status, Detection Rule); Analyze an investigation (Priority, Disposition); Modify Detection Rules (Rule Action, Exceptions). Lab identities only.

Why-no-detection — fields you write in the ticket
Path A:  Investigations  · filter asset + Detection Rule + UTC window
Quote:   Status + Priority + Detection Rule + Disposition
If empty:
Path B:  Detection Rules → Detection Rule Library → rule details
Quote:   Rule Action (Creates Investigations / Creates Alert /
         Tracks Notable Events / Assess Activity / Off)
Then:    Exceptions tab · Exception Name · exception matches
Residual: Asset Details → Search Related Logs (widen past 1 hour)

Side C — Last scan + vulnerability (VM proof)

  1. Quote the correct clock

    Sites page / site detail: Last Scan (or Last Scanned) is the last discovery, vulnerability, or policy scan — click the date to open that scan. View Scan History on the site. Deployment-wide: Administration → Scans > History → View current and past scans. Query Builder: Last Scan Time = last Insight Agent assessment. Asset Details: Last On Demand Agent Scan (Complete + date/time). Do not tell change-control “we scanned yesterday” from the agent clock when they asked for a vulnerability scan.

  2. Completed is not authenticated

    After the scan, Administration → Scans → History → the Scan Name → Completed AssetsAuthentication column. Official success line in the scan log: “A set of [service_type] administrative credentials have been verified.” Test Credentials on the shared or site-specific credential before you call the box clean. Zero local vulns after an unauthenticated ping is not a clean box. Source: Configuring site-specific scan credentials; Using the Insight Agent with InsightVM.

  3. Open the finding, not the weekly PDF

    Security Console Vulnerabilities icon → Vulnerability Listing. Click the vulnerability, then the asset. Quote First Found (date the vulnerability was first detected in the environment), risk score, CVSS (default CVSS:3.1 when present), Severity (Moderate 0–3.4 / Severe 3.5–7.4 / Critical 7.5–10 on Rapid7’s CVSSv2-derived severity), Instances, exploit / malware kit icons. Then check whether a vulnerability exception already exists (reason, scope, expiry). Source: Working with vulnerabilities; Working with vulnerability exceptions.

Green success on each side

6. Five tickets as full stories

These five land every quarter. Memorise first tool + proof field. Times and identities below are lab-only.

TicketSymptomFirst toolProof field
R7EVD-01WFH laptop: “is Rapid7 even seeing this host?”Assets / Asset DetailsHostname + IP + Assessed vs Unassessed
R7EVD-02Pune DC silent since 02:00; Log Search emptyData Collection Health → CollectorsCollector Active/Inactive + event source Running + incoming
R7EVD-03PowerShell on 10.10.8.22; “why no detection?”Investigations + Detection Rule LibraryStatus + Detection Rule + Rule Action + Exceptions
R7EVD-04Weekly PDF thin; “when did we last scan SITE-LAB-01?”Site Last Scan / Query Builder Last Scan TimeLast Scan (engine) vs Last Scan Time (agent)
R7EVD-05“Critical CVE — isolate it” on a freeze hostVulnerabilities → asset listingFirst Found + risk + exception reason/expiry

R7EVD-01 — Prove the asset (Assets / Asset Details)

01:42 · P2. Priya on a hotel network. Screenshot of an InsightIDR dashboard tile. L1 already drafted Quarantine Asset “just in case.”

First tool: InsightVM Assets search win-l2-08.lab.example / 10.10.8.22. If VM is empty, InsightIDR global search → Asset Details.

If missing: no Assessed row, no Unassessed / Discovered row, no Asset Details. Quote that absence. Next check is site include (IP range / asset group) or Insight Agent install — not Detection Rules, not Take Action.

If present: quote hostname, IP, site SITE-LAB-01, Assessed vs Unassessed, agent present or not. You are now allowed to open collector health (IDR ticket) or Last Scan (VM ticket). Asset Details is not First Found and is not Rule Action.

Trap

Do not quarantine a hostname from Slack. The proof is the Assets / Asset Details record. Unassessed is not “Rapid7 is down” — it is discovered, not yet assessed.

R7EVD-02 — Prove the collector (Data Collection Health)

02:05 · P1. Pune AD authentications vanished after a 02:00 firewall change. Event source card still says Running. Someone wants every detection rule set to Creates Investigations.

First tool: Data Collection → Data Collection Health → Collectors. Filter r7-col-pune-01.

Proof field: Collector Inactive (official: Collector Shows as Inactive), or Active but Event Sources → Monitor Health incoming = 0 in the ticket window, with an orange/red error. Running + incoming 0 is still a pipe ticket. Restore 443 to the regional data.insight.rapid7.com endpoint (and the documented ingress / S3 destinations), restart the Collector service, then wait for incoming and the first Log Search row. Do not flip Rule Action on an Inactive collector.

Close

I would not rewrite detections. I would quote Collector Inactive (or Running + incoming 0 + the error). Service restart, then Monitor Health incoming in the same UTC window. Email can also fire when a collector is offline 15 minutes — that mail is a pointer, not the close.

R7EVD-03 — Prove the detection (Investigations + Rule Action)

02:20 · P2. Endpoint owner: “we saw encoded PowerShell on 10.10.8.22 — why no Rapid7 detection?” Collector is Active. Asset exists. L1 wants Quarantine Asset.

First tool: Investigations filtered to that asset + last 24 hours + the expected Detection Rule. Then Detection Rules → Detection Rule Library → that rule.

Proof field: either an investigation with Status + Detection Rule + Disposition, or an empty queue explained by Rule Action = Off (or Assess Activity / Tracks Notable Events) or an Exceptions match on that asset/user. Throttling is official too: 20 alerts per asset per minute, 500 per org per minute — a flood can be missing investigations without the platform being down.

Close

Empty Investigations is allowed when Rule Action is Off or an exception overrode it. Quote the Rule Action and the exception name. Quarantine is InsightIDR Take Action after you have behavior evidence — it is not how you debug a silent rule.

R7EVD-04 — Prove the last scan (Last Scan vs Last Scan Time)

02:40 · P3. Weekly PDF for SITE-LAB-01 looks thin. L1 says “agent is current” and wants Scan Now of the whole VLAN.

First tool: site detail Last Scan / Last Scanned (click the date). Then Query Builder Last Scan Time for 10.10.8.22. Then Asset Details Last On Demand Agent Scan if someone already kicked an agent scan.

Proof field: Last Scan = 2026-07-12 03:10 UTC (discovery or vuln — say which). Last Scan Time = 2026-08-16 01:05 UTC (Insight Agent). Those are different clocks. If Last Scan is a discovery-only run, you have not assessed vulnerabilities. If Authentication on Completed Assets is blank, you have not authenticated. Test Credentials before you call it clean.

Trap

Scan Now of the VLAN is change-control, not proof. Last Scan Time moving is not a vulnerability scan. Risk scores are only computed from assets with completed scan status — in-progress assets reuse the last completed result.

R7EVD-05 — Prove the vulnerability (First Found + exception)

03:00 · P2. Slack: “Critical CVE — isolate it.” Same host 10.10.8.22 is in a change freeze. Someone pasted a CVSS 9.8 from a blog.

First tool: Security Console Vulnerabilities → the finding → the asset. Factory reminder: isolation is an InsightIDR / InsightConnect action. A critical CVE is an InsightVM finding.

Proof field: First Found on this asset, risk score, Severity, Instances, exploit / malware-kit icon if present, and whether a vulnerability exception already exists (reason, scope, expiry). If First Found is fourteen months old and an exception expires next week, you do not quarantine at 03:00 — you name the freeze owner. If First Found is tonight and exploitable with a Metasploit module, you still open IDR Asset Details / Investigations before Take Action, because contain needs a single owner.

Close

I would not isolate from CVSS. I would paste First Found + risk + exception expiry (or “no exception”). Then I would name the contain owner only if InsightIDR also has behavior — see the session factory.

7. Traps + close-the-ticket proof

Proof · named field, then Closed
Operations desk with abstract green health checks and one highlighted Rapid7 proof field
Notice: the close is a named column on a timestamp, not a screenshot of the InsightIDR home tile.
You seeWeak closeStrong close
No Assets / Asset Details row“Rapid7 is down” / Quarantine AssetQuote the missing record; fix site include or agent install; re-search Assets
Unassessed / Discovered only“Host is clean”Discovered ≠ assessed. Assign and scan (or install the Insight Agent)
Collector InactiveSet every Rule Action to Creates InvestigationsQuote Inactive; restart Collector; re-read Monitor Health incoming
Event source Running, Log Search empty“Detections are broken”Collector Inactive, blocked port, or unparsed / non-English / test env
Empty InvestigationsQuarantine the hostRule Action Off / Assess Activity / exception matches / throttle
Rule Action = Tracks Notable Events“InsightIDR missed it”Notable events attach to related investigations — they do not open a new one
Last Scan Time is fresh“We scanned yesterday”That is the Insight Agent clock. Quote Last Scan (engine) if they asked for a vuln scan
Scan completed, zero local vulns“Box is clean — isolate anyway”Authentication column + Test Credentials. Completed ≠ authenticated
CVSS 9.8 in SlackTake Action → Quarantine AssetFirst Found + risk + exception on this asset; product pick from the factory
Dashboard tile green“Rapid7 is working”Green is not hostname + IP + Active + Rule Action + Last Scan + First Found
Proof checklist before you leave the bridge
Interview close

I name the question, then the first tool, then one official field. Assets / Asset Details proves the host. Data Collection Health proves the collector. Investigations + Rule Action prove why a detection did or did not land. Last Scan versus Last Scan Time proves the assessment clock. First Found + exception proves the CVE. I do not quarantine, Scan Now, or flip a rule until that field is on the ticket. Product pick and double-isolate: session factory.

Knowledge check

Six night-shift judgments. Each maps to a first tool or a proof field. Check answers, then Reset if you picked the wrong surface.

Q1

WFH user: “Is Rapid7 even seeing this laptop?” You have not opened a console yet. First proof?

Correct: b. Official Assets / Asset Details. No record means there is no investigation and no First Found to hunt. Re-read Side A step 1 and R7EVD-01.
Q2

Pune AD went silent at 02:00. The event source card still says Running. Log Search is empty. First tool + field?

Correct: c. Official pipe path. Running is not incoming data. Collector Inactive or incoming 0 is the ticket. Re-read Side A steps 2–4 and R7EVD-02.
Q3

Encoded PowerShell on 10.10.8.22. Collector is Active. Asset exists. Investigations for that asset is empty. What do you quote first?

Correct: a. Official Rule Actions and exception-level override. Empty Investigations is data. Re-read Side B and R7EVD-03.
Q4

L1 says “the agent is current, so SITE-LAB-01 was scanned yesterday.” Which field actually proves an Insight Agent assessment vs an engine scan?

Correct: b. Official Last Scan vs Last Scan Time split. Re-read the caveat in §4, Side C step 1, and R7EVD-04.
Q5

Slack: “Critical CVE — isolate it.” The host is in a change freeze. Which proof field closes R7EVD-05?

Correct: d. Official First Found / risk / exception. Isolation is an IDR action; a CVE is a VM finding. Re-read Side C step 3, R7EVD-05, and the factory link.
Q6

Data Collection Health shows Collector Shows as Inactive. What is that sentence allowed to mean?

Correct: a. Official Inactive wording. Empty Investigations / Log Search is expected until the pipe is up. Re-read Flow 2 bottom box and R7EVD-02.

Sources

Related: Blog 1 · Rapid7 session factory · InsightIDR UEBA investigation · InsightVM + Exposure Command · Rapid7 Security Platform hub