Ellipse Gradient for Header

Rubrik Security Cloud Integration Guide

Integrate Rubrik Security Cloud with enterprise systems through its GraphQL API, selective webhook notifications, OAuth 2.0, and Martini workflows.

Rubrik Security Cloud integration options at a glance

Rubrik Security Cloud is primarily integrated through its GraphQL API, which supports queries and mutations for inventory, protection, monitoring, compliance, jobs, and supported recovery operations. Rubrik also provides webhook-style notifications for selected operational and alert events, although coverage is not universal. OAuth 2.0 service-account authentication supplies bearer tokens for tenant-specific API endpoints. Martini can consume GraphQL queries, submit mutations, poll asynchronous jobs, receive selected notifications, and reconcile missed events through scheduled workflows. REST APIs exist in parts of the broader Rubrik portfolio, but their availability for a specific RSC tenant and operation should be validated.

Integration pointSupported by Rubrik Security Cloud?Common use casesHow Martini supports it
GraphQL APIsYesRetrieve SLA Domains, Protected Objects, Virtual Machines, Filesets, Recovery Points, Jobs, Clusters, Organizations, compliance data, and supported operational details; submit supported administrative or recovery mutations.Martini can consume authenticated GraphQL queries and mutations, supply variables and pagination values, transform responses, and expose controlled APIs over Rubrik operations.
Webhooks / outbound callbacksLimitedReceive selected operational, alert, backup, compliance, anomaly, or job-related notifications. Coverage varies by event type and is not a complete event stream.Martini can expose an inbound API endpoint, validate and deduplicate notifications, enrich them through GraphQL, and route them to downstream systems.
Bulk / async / batch APIsLimitedMany Rubrik mutations and operational actions return asynchronous job or task references. General-purpose bulk support is operation-specific and should be confirmed.Martini can store job identifiers, poll status with bounded backoff, handle terminal states, and reconcile indeterminate operations.
AuthenticationYesOAuth 2.0 service-account client credentials provide bearer tokens for tenant- and region-specific Rubrik Security Cloud API endpoints.Martini can keep client credentials, tenant URLs, token endpoints, and environment configuration in secrets and use bearer authentication in workflows.
REST APIsLimitedRubrik exposes REST APIs across parts of its broader product portfolio, but RSC integrations are primarily GraphQL. Availability must be validated for the target tenant and operation.Martini can consume a confirmed Rubrik REST endpoint, but implementations should not assume Rubrik CDM REST endpoints are interchangeable with RSC APIs.
File / attachment APIsNot confirmedNo general-purpose attachment API for RSC objects was confirmed. File recovery or file-search capabilities should be evaluated separately.Martini can process API responses and generate files where appropriate, but should not assume arbitrary protected content can be downloaded as an attachment.
Database / analytics accessNoDirect access to Rubrik Security Cloud underlying databases was not identified. Reporting should use APIs, notifications, exports, or approved downstream integrations.Martini can normalize supported API data and write it to an approved database or analytics destination without requiring direct Rubrik database access.
SDKsNot confirmedRubrik provides developer resources and API tooling, but a specific SDK is not required as the integration contract is the documented RSC API schema.Martini can consume the API directly over HTTPS and GraphQL request handling without depending on a particular SDK.

How Rubrik Security Cloud exposes data and business events

Rubrik Security Cloud GraphQL APIs

Rubrik Security Cloud provides a GraphQL API for administrative, protection, inventory, monitoring, compliance, and supported recovery queries and mutations. The available schema and fields depend on the tenant and enabled capabilities.

Martini implementation pattern

Martini implementation pattern: Martini obtains an OAuth bearer token, submits parameterized GraphQL queries or mutations, validates both HTTP and GraphQL-level errors, maps responses into canonical structures, and invokes downstream workflows or APIs.

Implementation sequence

Obtain an OAuth 2.0 access token
Submit a parameterized GraphQL query or mutation
Validate HTTP and GraphQL response errors
Map the response into the target model
Write the result or capture the returned job identifier
Poll asynchronous jobs when required

Rubrik Security Cloud webhook notifications

Rubrik Security Cloud supports webhook-style notifications or integrations for selected operational and alert events. Notifications are selective and may contain an event reference rather than a complete current object.

Martini implementation pattern

Martini implementation pattern: Martini exposes an inbound endpoint, validates the available authentication or signature controls, acknowledges quickly, deduplicates the notification, enriches it through GraphQL, and routes it to the appropriate target system.

Implementation sequence

Receive the Rubrik notification
Validate authentication, content type, and replay controls
Deduplicate the event using an identifier or deterministic hash
Retrieve authoritative object or job data when needed
Apply routing and business rules
Deliver the outcome and record the correlation reference

Rubrik Security Cloud asynchronous operations

Many Rubrik operations return a job or task reference instead of a completed result. Recovery, archival, replication, and other actions therefore require status tracking.

Martini implementation pattern

Martini implementation pattern: Martini submits the supported mutation, persists the returned job identifier, polls according to bounded backoff rules, and routes success, failure, cancellation, timeout, or indeterminate status separately.

Implementation sequence

Validate the requested operation and permissions
Submit the Rubrik mutation
Store the returned job identifier
Poll the job status with bounded backoff
Handle terminal and indeterminate states
Notify the caller or downstream system

Rubrik Security Cloud scheduled reconciliation

Scheduled GraphQL queries provide authoritative correction for missed, delayed, duplicated, or unsupported notifications. This is important because webhook coverage does not include every object or state transition.

Martini implementation pattern

Martini implementation pattern: A scheduled workflow retrieves paginated data, applies incremental filters or checkpoints where supported, compares source state with the target, and performs idempotent upserts and exception handling.

Implementation sequence

Start the scheduled synchronization
Load the prior checkpoint and tenant configuration
Retrieve paginated Rubrik objects
Map and compare source and target state
Perform idempotent upserts
Store the new checkpoint and report exceptions

Common Rubrik Security Cloud integration patterns

Pattern 1: Report backup compliance to an analytics platform

When to use this pattern

Use this pattern when operations or governance teams need a consolidated view of SLA Domains, Protected Objects, Recovery Points, and compliance status. It identifies workloads that are unprotected, outside policy, or missing recent recovery points.

Integration direction
Rubrik Security Cloud
Martini
Splunk
Example Mapping
Rubrik Security Cloud FieldCanonical FieldTarget Field
SLA Domain nameprotectionPolicyNamepolicy_name
Protected Object IDassetIdasset_id
Recovery Point timestamplatestRecoveryPointAtlatest_recovery_at
Compliance statusprotectionCompliancecompliance_status
Martini implementation pattern

A scheduled Martini workflow uses paginated GraphQL queries, normalizes policy and workload data, enriches assets with ownership identifiers, applies compliance rules, and writes idempotent analytics events. Query failures and partial results are captured for retry and reconciliation.

Martini capabilities used
  • workflows
  • GraphQL API consumption
  • scheduling
  • data mapping
  • business rules
  • error handling

Pattern 2: Route Rubrik alerts to incident management

When to use this pattern

Use this pattern when selected Rubrik notifications should create or update incidents for failed jobs, compliance exceptions, anomalies, or recovery events.

Integration direction
Rubrik Security Cloud
Martini
ServiceNow
Example Mapping
Rubrik Security Cloud FieldCanonical FieldTarget Field
Event or job IDexternalCorrelationIdcorrelation_id
Alert severitypriorityimpact
Protected ObjectaffectedAssetconfiguration_item
Event statusincidentStatestate
Martini implementation pattern

Martini receives the notification, validates the request, deduplicates by event or job reference, enriches incomplete payloads through GraphQL, applies severity and ownership rules, and creates or updates the ServiceNow incident. Transient target errors follow a retry path.

Martini capabilities used
  • API exposure
  • webhook consumption
  • data enrichment
  • business rules
  • idempotent upsert
  • error handling

Pattern 3: Orchestrate an approved recovery request

When to use this pattern

Use this pattern when an internal application needs a controlled API boundary for requesting Rubrik recovery operations without exposing Rubrik credentials or mutation details.

Integration direction
Internal recovery application
Martini
Rubrik Security Cloud
Example Mapping
Rubrik Security Cloud FieldCanonical FieldTarget Field
Requested workload IDassetIdprotectedObjectId
Requested recovery pointrecoveryPointIdrecoveryPointId
Requester identityrequestedByauditContext
Rubrik job statusoperationStatusresponse.status
Martini implementation pattern

A Martini API validates the workload, Recovery Point, requester, and approval state, then submits the supported GraphQL mutation. The workflow stores the job reference, polls to a bounded terminal state, and returns a controlled response while routing failures to operations.

Martini capabilities used
  • REST API exposure
  • GraphQL API consumption
  • validation
  • business rules
  • asynchronous orchestration
  • retry handling

Pattern 4: Synchronize protection inventory with a CMDB

When to use this pattern

Use this pattern when a configuration or asset-management platform needs current Clusters, Virtual Machines, Filesets, Protected Objects, and SLA Domains with repeatable reconciliation.

Integration direction
Rubrik Security Cloud
Martini
ServiceNow
Example Mapping
Rubrik Security Cloud FieldCanonical FieldTarget Field
Rubrik object IDsourceAssetIdcorrelation_id
Virtual Machine nameassetNamename
Cluster nameprotectionPlatformu_protection_cluster
SLA DomainprotectionPolicyu_sla_domain
Martini implementation pattern

A scheduled workflow retrieves only required fields using pagination and incremental filters where supported, maps relationships into the CMDB model, and performs idempotent upserts. Checkpoints, source timestamps, and failed pages are retained for reconciliation.

Martini capabilities used
  • scheduled workflows
  • GraphQL API consumption
  • pagination
  • data mapping
  • idempotent synchronization
  • monitoring

Applications commonly integrated with Rubrik Security Cloud

Rubrik Security Cloud data and notifications can be coordinated with operational, security, infrastructure, and collaboration applications. Martini can combine Rubrik API queries, selected notifications, business rules, and target-system APIs while keeping credentials and asynchronous job handling in controlled workflows.

Application Scenario Direction Martini Pattern
ServiceNow Create incidents or change records for backup failures, compliance exceptions, security alerts, and approved recovery requests. Rubrik Security Cloud → Martini → ServiceNow Receive selected Rubrik notifications or poll GraphQL for authoritative status, enrich the event with job and workload details, apply severity and ownership rules, then create or update ServiceNow records with correlation identifiers.
Splunk Centralize Rubrik backup, job, compliance, and security-related data for operational and security analytics. Rubrik Security Cloud → Martini → Splunk Use scheduled paginated GraphQL queries and selected notifications, normalize Rubrik objects into an analytics model, and deliver filtered events or records through the target ingestion API.
Microsoft Sentinel Enrich security monitoring with Rubrik alerts and data-protection events. Rubrik Security Cloud → Martini → Microsoft Sentinel Ingest selected notifications, retrieve current Rubrik context when required, map events to the Sentinel ingestion model, and apply deduplication and retry handling.
Microsoft Teams Notify operations teams about failed jobs, policy exceptions, and recovery completion. Rubrik Security Cloud → Martini → Microsoft Teams Route selected webhook events or scheduled exception results through a Martini workflow, format concise notifications, and send them through the tenant's supported Teams integration method.
Slack Send selected operational or security notifications to response channels. Rubrik Security Cloud → Martini → Slack Validate and deduplicate Rubrik events, enrich them with GraphQL job or object data, apply channel-routing rules, and invoke the approved Slack API or webhook endpoint.
Jira Service Management Create operational issues for recurring protection failures and remediation work. Rubrik Security Cloud → Martini → Jira Service Management Poll or receive Rubrik events, map protection and compliance exceptions to Jira issue fields, upsert by a deterministic Rubrik reference, and retry transient target failures.
VMware vSphere Synchronize virtual-machine inventory and protection state or coordinate selected recovery workflows involving VMware workloads. VMware vSphere → Rubrik Security Cloud → Martini Use Rubrik GraphQL for protected VMware workload state and coordinate approved downstream actions through controlled Martini workflows, with identifier validation and asynchronous job tracking.
Amazon S3 Coordinate metadata, reporting, or governance workflows related to cloud storage and archival configurations. Rubrik Security Cloud → Martini → Amazon S3 Use Rubrik API data for control-plane metadata, transform it into a reporting or governance model, and write approved outputs to S3 using the applicable target integration.

How to build a Rubrik Security Cloud integration in Martini

Objective

Configure the Rubrik tenant or regional endpoint and OAuth 2.0 service-account authentication without embedding credentials in workflow logic.

Instructions in Martini

  • Store the client ID, client secret, token endpoint, tenant URL, and GraphQL endpoint as environment-specific secrets or configuration.
  • Use separate least-privilege service accounts for reporting, monitoring, recovery, and administration.
  • Configure TLS-protected HTTPS communication and bearer-token handling.

Objective

Select the trigger that matches the required freshness and event coverage rather than assuming that every Rubrik state change generates a notification.

Instructions in Martini

  • Use a Rubrik notification endpoint for selected operational or alert events.
  • Use a scheduler for inventory, compliance, and reconciliation workflows.
  • Use a Martini API when an internal application initiates a controlled Rubrik operation.

Objective

Receive notifications or query Rubrik Security Cloud through its GraphQL API using narrow, parameterized requests.

Instructions in Martini

  • Validate webhook requests before processing them.
  • Use GraphQL variables, pagination, and incremental filters where supported.
  • Retrieve authoritative object or Job data when a notification contains only a reference.

Objective

Coordinate enrichment, validation, target calls, and asynchronous Rubrik operations in a maintainable Martini workflow.

Instructions in Martini

  • Separate notification intake from longer enrichment and delivery work.
  • Persist correlation identifiers, checkpoints, and returned Rubrik Job references.
  • Route success, retryable failure, permanent failure, and indeterminate states separately.

Objective

Convert Rubrik objects and operational results into a canonical model for downstream systems.

Instructions in Martini

  • Map actual objects such as SLA Domains, Protected Objects, Recovery Points, and Jobs.
  • Normalize timestamps, identifiers, status values, and ownership attributes.
  • Select only required fields and redact sensitive payload data from logs.

Objective

Enforce protection, approval, routing, and duplicate-handling policies before writing data or starting operations.

Instructions in Martini

  • Validate workload and Recovery Point identifiers before recovery mutations.
  • Apply severity, ownership, and approval rules.
  • Use idempotent upserts and check current Job state before retrying side-effecting operations.

Common Rubrik Security Cloud data objects used in integrations

ObjectTypical UseCommon target systemsMartini handling
SLA DomainsRepresent protection frequency, retention, archival, replication, and related data-management policies.ServiceNow, Splunk, Microsoft Sentinel, SQL databases, reporting APIsMartini queries policy fields, normalizes them with workload and compliance results, and performs idempotent upserts or report generation.
Protected ObjectsRepresent workloads or assets protected by Rubrik, including virtual machines, databases, filesets, and cloud workloads.CMDBs, ServiceNow, Splunk, Microsoft SentinelMartini retrieves paginated object data, maps stable Rubrik identifiers to canonical asset fields, and reconciles protection state.
Virtual MachinesRepresent VMware and other supported virtual-machine assets managed and protected by Rubrik.VMware vSphere, CMDBs, ServiceNow, reporting platformsMartini synchronizes inventory and protection metadata, validates workload identifiers, and routes exceptions for remediation.
FilesetsRepresent file and directory protection definitions associated with physical or virtual hosts.CMDBs, compliance databases, ServiceNow, reporting APIsMartini queries Filesets where supported, maps host and policy relationships, and records synchronization checkpoints.
Recovery PointsRepresent point-in-time protected copies used for recovery validation, compliance, and recovery requests.ServiceNow, internal recovery portals, reporting systemsMartini validates requested Recovery Points before mutations and maps availability and timestamp data into controlled workflows.
JobsRepresent backup, archival, replication, recovery, and other asynchronous operations with status and progress.ServiceNow, Splunk, Microsoft Sentinel, operational dashboardsMartini stores job identifiers, polls status, applies timeout and retry rules, and correlates final outcomes with originating requests.

Authentication and security considerations

OAuth 2.0 service accounts

Rubrik Security Cloud integrations commonly use OAuth 2.0 client credentials with a Rubrik service account. Martini should store the client ID, client secret, token endpoint, tenant URL, and API endpoint as environment-specific secrets.

Least-privilege authorization

Rubrik roles and organization permissions determine which objects and operations a service account can access. Separate read-only reporting identities from accounts authorized to perform recovery or administrative mutations.

Webhook protection

For selected notifications, validate the authentication, signature, timestamp, content type, and replay controls available for the Rubrik configuration. Restrict the Martini endpoint and avoid logging tokens or unnecessary backup and infrastructure details.

Transport and data protection

Use TLS-protected HTTPS communication and limit sensitive payload retention. Backup, recovery, workload, and security-event data may disclose infrastructure details and should be handled according to organizational security requirements.

Operational considerations for Rubrik Security Cloud integrations

Pagination and rate limits

Large inventories should use the pagination model defined by the GraphQL schema, narrow field selection, incremental filters where supported, bounded concurrency, and backoff. Confirm quotas and service limits for the tenant.

Jobs and retries

Do not interpret a successful mutation response as proof that an operation completed. Store the Job reference, poll with a maximum duration, and distinguish failed, canceled, expired, timed-out, and indeterminate states.

Idempotency and duplicates

Webhook deliveries may be duplicated or arrive out of order. Use event IDs, Job IDs, deterministic hashes, or supported idempotency keys. Before retrying side-effecting mutations, check whether the original operation was accepted.

Schema and consistency

GraphQL schemas can evolve. Keep queries version-controlled, avoid unnecessary fields, monitor deprecations, and record source timestamps and Rubrik identifiers. Use scheduled reconciliation because notifications are selective.

Testing and observability

Test authentication, GraphQL-level errors, authorization failures, pagination, notification payload variations, and asynchronous terminal states. Correlate Martini executions with Rubrik Job IDs while redacting sensitive payloads from logs.

Why use Martini instead of scripts or point-to-point integrations?

Orchestrate beyond a single API call

Scripts often become difficult to govern when they must combine webhook intake, GraphQL enrichment, approval rules, target-system updates, and asynchronous Job polling. Martini models that behavior as maintainable workflows and APIs.

Separate integration logic from credentials

Martini centralizes environment-specific endpoints and OAuth secrets while allowing workflows to remain reusable across development, test, and production tenants.

Handle operational complexity

Martini provides a structured place for pagination, transformations, validation, retries, duplicate handling, reconciliation, monitoring, and controlled error paths instead of duplicating those concerns across point-to-point scripts.

Expose reusable enterprise services

A Martini API can present a normalized façade for Rubrik operations, enforce business and approval rules, and keep Rubrik-specific schema and credentials behind a controlled enterprise boundary.

Frequently asked questions

How can Rubrik Security Cloud be integrated with enterprise systems?

Rubrik Security Cloud is primarily integrated through its GraphQL API for inventory, protection, compliance, monitoring, job, and supported recovery operations. It also provides selective webhook-style notifications, while OAuth 2.0 service-account authentication secures API access. Scheduled GraphQL reconciliation can supplement notification coverage.

Can Martini integrate with Rubrik Security Cloud?

Yes. Martini can consume the Rubrik Security Cloud GraphQL API, authenticate with OAuth 2.0 bearer tokens, receive selected Rubrik webhook notifications through an exposed API, orchestrate asynchronous Jobs, and map results to enterprise applications.

Do I need a connector to integrate Rubrik Security Cloud with Martini?

No. A dedicated Rubrik connector is not required. Martini can integrate using Rubrik Security Cloud's confirmed native mechanisms, primarily its GraphQL API, OAuth 2.0 authentication, and selected webhook-style notifications.

Is there any extra Lonti cost to integrate Rubrik Security Cloud with Martini?

Lonti does not charge an additional per-connector or per-vendor fee to integrate Rubrik Security Cloud. The integration is subject to the provisioned capacity of the Martini environment. Separate costs may apply from Rubrik, cloud infrastructure, or other third-party systems based on subscription, usage, and deployment model.

Which Rubrik Security Cloud integration methods should be used?

GraphQL is the primary and recommended integration method for RSC. Selective webhook notifications are useful for near-real-time operational handling, while scheduled GraphQL queries provide reconciliation and complete synchronization. REST APIs should be used only after validating availability for the specific RSC tenant and operation; SOAP was not confirmed.

Can Rubrik Security Cloud send events or webhooks to Martini?

Rubrik Security Cloud supports webhook-style notifications for selected events, but not necessarily every object change or state transition. Martini can receive those notifications, validate and deduplicate them, enrich them through GraphQL, and use scheduled reconciliation for missed or unsupported events.

How does synchronization and asynchronous job handling work?

Martini can use paginated GraphQL queries, stable Rubrik identifiers, incremental filters where supported, and checkpoints for synchronization. Rubrik mutations may return asynchronous Job references, so Martini should poll with bounded backoff and handle success, failure, cancellation, timeout, and indeterminate states separately.

Can Martini expose an API façade for Rubrik Security Cloud?

Yes. Martini can expose a controlled REST API that validates requests, applies approval and authorization rules, invokes supported Rubrik GraphQL mutations, hides Rubrik credentials, and returns a normalized status response. This is useful for recovery orchestration and internal self-service workflows.