Source

Wiz Webhook

Transform how security teams handle runtime alerts, cloud risks, and compliance needs with the Wiz Webhook and Cribl Stream integration.

About the Integration

Together, Cribl and Wiz enable you to enhance your security operations, improve data quality, and make more efficient use of your security tools. By leveraging a standard HTTP-based webhook, Stream can capture real-time alert data from Wiz, process it, and route it to your preferred destinations, whether that's a SIEM, data lake, or analytics tool.

Cribl Stream supports receiving Wiz Defend Alert data. Wiz Webhook, an HTTP-based Source, listens on a specific port, captures every HTTP request to that port, and creates a corresponding event that it pushes to its configured Event Breakers.

Benefits: 

  • Gain immediate visibility into your cloud security: Wiz’s agentless-first approach comprehensively scans across cloud resources, identifies risks, and prioritizes them.

  • Shape and route your data: Use Cribl Stream to flexibly transform and route data from Wiz to multiple destinations, enhancing overall data visibility and access.

  • Boost operational efficiency: Optimize data routing, reduce data redundancy, and enhance the overall operational efficiency of data security management.

  • Comprehensive risk Views: Facilitate audits and regulatory reporting by providing complete and easily accessible views of enterprise risks.

  • Simplify storage and compliance: Streamline the integration of compliance-focused data into long-term storage solutions to ease adherence to regulatory standards.

Read the integration blog post: https://cribl.io/blog/getting-started-with-the-wiz-webhook-source-in-cribl-stream/  

How to Get Data Flowing 

This is a built-in integration between Cribl Stream and Wiz.

  • Configure the Wiz Webhook source in Cribl Stream 

  • Create a token to authenticate to this new webhook. 

  • Configure the optional settings and optionally, adjust the TLS, Persistent Queue Settings, Processing and Advanced settings, or Connected Destinations. 

  • Select Save, then Commit and Deploy.

  • Provide the Cribl Stream URL when configuring the Wiz UI which you can find under the menu Products -> Cribl -> Data Sources.

  • From within the Wiz Webhook source, enter the port that Cribl Stream should have the webhook listen on for incoming connections from Wiz.  

  • Create your Authentication token which needs to be referred to from within the Wiz console to enable logging an external Cribl Stream instance.

  • Verify that data is making it to Cribl Stream by viewing the Live Data feed from the Source then configure routing to the destinations of your choosing.

Cribl, the Data Engine for IT and Security, empowers organizations to transform their data strategy. Customers use Cribl’s suite of products to collect, process, route, and analyze all IT and security data, delivering the flexibility, choice, and control required to adapt to their ever-changing needs.

We offer free training, certifications, and a free tier across our products. Our community Slack features Cribl engineers, partners, and customers who can answer your questions as you get started and continue to build and evolve. We also offer a variety of hands-on-Sandboxes for those interested in how companies globally leverage our products for their data challenges.