Source

Wiz API

Transform how security teams handle runtime alerts, cloud risks, and compliance needs with the Wiz API and Cribl Stream integration.

About the Integration

Cribl and Wiz simplify compliance adherence by integrating compliance-focused data into long-term retention systems – reducing the operational complexities. Combining Wiz’s deep cloud security analysis with Cribl’s powerful data processing capabilities helps organizations to quickly identify and address critical risks, misconfigurations, network exposures, and vulnerabilities across their cloud environments. 

Cribl Stream supports collecting data from the Wiz cloud security platform. The Wiz API Source will communicate with APIs that your organization’s Wiz portal exposes: Audit Logs, Configuration Findings (sometimes called Cloud Configuration), Issues, and Vulnerabilities.

Benefits: 

  • Gain immediate visibility into your cloud security: Wiz comprehensively scans across cloud resources, identifies risks, and prioritizes them.

  • Shape and route your data: Use Cribl Stream to flexibly transform and route data from Wiz to multiple destinations, enhancing overall data visibility and access.

  • Boost operational efficiency: Optimize data routing, reduce data redundancy, and enhance the overall operational efficiency of data security management.

  • Comprehensive risk views: Facilitate audits and regulatory reporting by providing complete and easily accessible views of enterprise risks.

  • Simplify storage and compliance: Streamline the integration of compliance-focused data into long-term storage solutions to ease adherence to regulatory standards.

How to Get Data Flowing 

This is a built-in integration between Crib and Wiz. 

  • From within the Wiz API source, enter the following Wiz provided information:  GraphQL endpoint, Authentication URL, Client ID, and the Client Secret.

  • You can enable the collection of Audit, Configuration, Issues, and Vulnerability findings.

  • Set the desired API query frequency and optionally modify the Content Query to fine tune what is retrieved from the Wiz API Endpoint.

  • Enable State tracking to ensure there are no gaps or overlaps in the retrieved data.

  • Click Save, then Commit & Deploy.

  • Verify that data is making it to Cribl Stream by viewing the Live Data feed from the Source then configure routing to the destinations of your choosing.

Cribl, the Data Engine for IT and Security, empowers organizations to transform their data strategy. Customers use Cribl’s suite of products to collect, process, route, and analyze all IT and security data, delivering the flexibility, choice, and control required to adapt to their ever-changing needs.

We offer free training, certifications, and a free tier across our products. Our community Slack features Cribl engineers, partners, and customers who can answer your questions as you get started and continue to build and evolve. We also offer a variety of hands-on-Sandboxes for those interested in how companies globally leverage our products for their data challenges.