About the Integration
The native Wiz Defend Destination in Cribl Stream uses an optimized, HEC-based webhook to reliably deliver curated security data into the Wiz Defend platform via a dedicated Cribl Stream connector. Security teams get immediate visibility into cloud threats with full context, can correlate Wiz alerts across environments, and cut mean time to respond (MTTR) while controlling storage and egress by sending only the right data to each tool.
Benefits:
Faster investigations and reduced MTTR: By processing logs in real-time, Cribl Stream accelerates delivery to Wiz Defend so teams move from hours-long investigations to minutes-level response windows. This means faster triage, threat hunting, and remediation by unifying runtime alerts, cloud risks, and enriched context into actionable views.
Enhanced security posture and visibility: Close visibility gaps in multi-cloud estates by streaming sources like CloudTrail and other cloud telemetry into Wiz Defend for continuous, context-rich monitoring. Security teams can proactively detect threats, track compliance drift, and correlate Wiz alerts with upstream signals across accounts, regions, and providers.
Flexible, scalable security operations: Route processed Wiz Defend-relevant data not only to Wiz, but to SIEM, SOAR, data lakes, or Cribl Lake and Search too, so teams can consolidate tooling without losing optionality. As cloud environments grow, this fan-out model reduces integration overhead, keeps pipelines consistent, and scales security operations without ballooning data and infrastructure costs.
How to Get Data Flowing
This is a built-in integration between Cribl Stream and Wiz.
Configure a Wiz Defend Destination in Cribl Stream:
The Wiz Defend console will provide you with the following values that need to be entered into the Wiz Defend Configure -> General Settings menu:
Wiz Data Center (example: us1, us3, eu3, etc).
Wiz Environment.
Wiz Connector ID. this is a unique identifier for the specific Cribl Connector in Wiz Defend (alphanumeric format: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx)
Wiz Defend Source Type. This must match the specific source type name in Wiz Defend that will parse the data sent from Cribl Stream.
Authentication token.
Select Save to finalize your new Wiz Defend Destination configuration.
Repeat the above for each data source you need to send to Wiz Defend. Each Wiz Defend Destination supports, by design, assigning a single sourcetype. Each Destination will have a corresponding Wiz Connector ID associated with it.
Configure your routing to send your desired data source(s) into your configured Wiz Destination(s).
Please note that there are no tagging requirements or modifications of the original events prior to sending to the Wiz Defend Destination tile. The Wiz Defend tile embeds the configuration context into the connection when sending events in their original raw format.