About the Integration
Together, Cribl and Wiz enable you to enhance your security operations, improve data quality, and make more efficient use of your security tools. By leveraging a standard HTTP-based webhook, Stream can capture real-time alert data from Wiz, process it, and route it to your preferred destinations, whether that's a SIEM, data lake, or analytics tool.
Cribl Stream supports receiving Wiz Defend Alert data. Wiz Webhook, an HTTP-based Source, listens on a specific port, captures every HTTP request to that port, and creates a corresponding event that it pushes to its configured Event Breakers.
Benefits:
Gain immediate visibility into your cloud security: Wiz’s agentless-first approach comprehensively scans across cloud resources, identifies risks, and prioritizes them.
Shape and route your data: Use Cribl Stream to flexibly transform and route data from Wiz to multiple destinations, enhancing overall data visibility and access.
Boost operational efficiency: Optimize data routing, reduce data redundancy, and enhance the overall operational efficiency of data security management.
Comprehensive risk Views: Facilitate audits and regulatory reporting by providing complete and easily accessible views of enterprise risks.
Simplify storage and compliance: Streamline the integration of compliance-focused data into long-term storage solutions to ease adherence to regulatory standards.
Read the integration blog post: https://cribl.io/blog/getting-started-with-the-wiz-webhook-source-in-cribl-stream/
How to Get Data Flowing
This is a built-in integration between Cribl Stream and Wiz.
Configure the Wiz Webhook source in Cribl Stream
Create a token to authenticate to this new webhook.
Configure the optional settings and optionally, adjust the TLS, Persistent Queue Settings, Processing and Advanced settings, or Connected Destinations.
Select Save, then Commit and Deploy.
Provide the Cribl Stream URL when configuring the Wiz UI which you can find under the menu Products -> Cribl -> Data Sources.
From within the Wiz Webhook source, enter the port that Cribl Stream should have the webhook listen on for incoming connections from Wiz.
Create your Authentication token which needs to be referred to from within the Wiz console to enable logging an external Cribl Stream instance.
Verify that data is making it to Cribl Stream by viewing the Live Data feed from the Source then configure routing to the destinations of your choosing.