Set filtering for the Wiz Test Results Integration
Set the filtering values to import the cloud test results data that you want.
시작하기 전에
Role required: sn_vul_wiz.configure_integration
프로시저
- Navigate to All > Wiz Vulnerability Integration > Administration > Configuration.
- Select the Test Results Configuration tab.
-
Fill in the fields.
For some fields, you can specify multiple values. --None-- is the (default). If --None-- remains selected for a field, no data is imported for this field.주:Host configurations from Wiz are not imported.
If displayed select the lock icons (
) and (
) to edit and lock your edits.
Select the Add/Remove multiple icon (
) to open the Edit members modal.
Field Description Severity Choose one for Severity filtering: - --None--
- LOW
- MEDIUM
- HIGH
- CRITICAL
- NONE - Return findings with no available severity values.
You might prefer to start with HIGH or CRITICAL to limit your import to findings of critical importance.
Project ID Specify only Cloud Configuration findings for Projects, for example, Named "Project ID". Cloud platform Configuration findings by Cloud platform. You can specify multiple values, for example, AWS, GitHub, Terraform, OpenAI, GKE, OKE, EKS, AKS. Subscription ID Specify by entering subscription ID. You can specify multiple values in an array. Resource Status Specify by status: - --None--
- Active
- Error
- Inactive
Framework Category Enter security frameworks, security subcategories, or security categories. You can specify multiple values. Resource type Select Add/Remove multiple icon to display the modal. Move your choices to the right column and select Save. Or, search for an asset target record type, for example, FIREWALL. You also have the open to add a new resource type record.
Native type Specify findings based on the native type of the cloud resource, for example, bucket. Has remediation Specify findings with (TRUE), without (FALSE) remediation instructions, or --None--. Status Filter by status: - --None--
- OPEN
- RESOLVED
First Pagination. Enter a value. You might prefer to start with 500. Fetch rejected findings Select this check box if you want to import Cloud test results in a failed state (rejected) from Wiz. If not selected, failed Cloud test results reported by Wiz are not imported. If imported, these test results remain in a failed state but are not rolled up to Configuration Compliance findings.
Close rejected findings Select this check box if you want to import failed Cloud test results reported by Wiz and automatically close them after import. If not selected, these test results remain in a failed state but are neither closed nor rolled up to Configuration Compliance findings.
-
Select Save and test.
If the credentials have been saved and validated successfully a message is displayed. You can select filtering for another integration import.