Destination

Wiz Defend

Gain immediate visibility into cloud threats and reduce MTTR with the Wiz Defend and Cribl Stream integration.

About the Integration 

The native Wiz Defend Destination in Cribl Stream uses an optimized, HEC-based webhook to reliably deliver curated security data into the Wiz Defend platform via a dedicated Cribl Stream connector. Security teams get immediate visibility into cloud threats with full context, can correlate Wiz alerts across environments, and cut mean time to respond (MTTR) while controlling storage and egress by sending only the right data to each tool.

Benefits: 

  • Faster investigations and reduced MTTR: By processing logs in real-time, Cribl Stream accelerates delivery to Wiz Defend so teams move from hours-long investigations to minutes-level response windows. This means faster triage, threat hunting, and remediation by unifying runtime alerts, cloud risks, and enriched context into actionable views.

  • Enhanced security posture and visibility: Close visibility gaps in multi-cloud estates by streaming sources like CloudTrail and other cloud telemetry into Wiz Defend for continuous, context-rich monitoring. Security teams can proactively detect threats, track compliance drift, and correlate Wiz alerts with upstream signals across accounts, regions, and providers.

  • Flexible, scalable security operations: Route processed Wiz Defend-relevant data not only to Wiz, but to SIEM, SOAR, data lakes, or Cribl Lake and Search too, so teams can consolidate tooling without losing optionality. As cloud environments grow, this fan-out model reduces integration overhead, keeps pipelines consistent, and scales security operations without ballooning data and infrastructure costs.

How to Get Data Flowing 

This is a built-in integration between Cribl Stream and Wiz.

  • Configure a Wiz Defend Destination in Cribl Stream:

    • The Wiz Defend console will provide you with the following values that need to be entered into the Wiz Defend Configure -> General Settings menu:

      • Wiz Data Center (example: us1, us3, eu3, etc).

      • Wiz Environment.

      • Wiz Connector ID. this is a unique identifier for the specific Cribl Connector in Wiz Defend (alphanumeric format: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx)

      • Wiz Defend Source Type. This must match the specific source type name in Wiz Defend that will parse the data sent from Cribl Stream.

      • Authentication token.

    • Select Save to finalize your new Wiz Defend Destination configuration.

  • Repeat the above for each data source you need to send to Wiz Defend. Each Wiz Defend Destination supports, by design, assigning a single sourcetype. Each Destination will have a corresponding Wiz Connector ID associated with it.

  • Configure your routing to send your desired data source(s) into your configured Wiz Destination(s).

Please note that there are no tagging requirements or modifications of the original events prior to sending to the Wiz Defend Destination tile. The Wiz Defend tile embeds the configuration context into the connection when sending events in their original raw format.

Cribl, the Data Engine for IT and Security, empowers organizations to transform their data strategy. Customers use Cribl’s suite of products to collect, process, route, and analyze all IT and security data, delivering the flexibility, choice, and control required to adapt to their ever-changing needs.

We offer free training, certifications, and a free tier across our products. Our community Slack features Cribl engineers, partners, and customers who can answer your questions as you get started and continue to build and evolve. We also offer a variety of hands-on-Sandboxes for those interested in how companies globally leverage our products for their data challenges.