Set filtering for the Wiz Host Vulnerabilities Integration

  • Release version: Zurich
  • Updated December 5, 2025
  • 2 minutes to read
  • Set the filtering values to import the host vulnerability data that you want.

    Before you begin

    Role required: sn_vul_wiz.configure_integration

    Procedure

    1. Navigate to All > Wiz Vulnerability Integration > Administration > Configuration.
    2. If not already selected, select the Host Vulnerabilities Configuration tab.
    3. Fill in the fields.
      These fields that are displayed provide you with filters to import basic host vulnerability data. Refer to the following tables for more information.
      Field Description
      First Pagination. Enter a value. You might prefer to start with 1000.
      Severity Finding severity. None is the default. If selected, this indicates you don’t want to import any data for this field. You can specify multiple values:
      • NONE - Return assets with no available severity values.
      • LOW
      • MEDIUM
      • HIGH
      • CRITICAL
      Resource Status Return only vulnerability findings for assets with these statuses. You can specify multiple values:
      • None (default) - If selected, this indicates you do not want to import any data for this field.
      • Active
      • Error
      • Inactive

      To view more filtering options, select the Advanced check box.

    4. Select the Advanced check box to view more filtering options.

      For most fields, you can specify multiple values. --None-- is the (default). If --None-- remains selected for a field, no data is imported for this field.

      If displayed select the lock icons (An closed padlock icon that indicates the field is locked and not editable.) and (An opened padlock icon that indicates the field is unlocked and editable.) to edit and lock your edits.

      Field Description
      Detection Method Filter on vulnerability findings found by these detection methods:
      • --None--
      • DEFAULT_PACKAGE
      • FILE_PATH
      • INSTALLED_PROGRAM
      • INSTALLED_PROGRAM_BY_SERVICE
      • LIBRARY
      • OS
      • PACKAGE
      Vulnerability Filter on vulnerability findings with matching external ID(s) that you enter, for example, CVE-1234-5678,CVE-9110-26117.
      Status Filter by finding status:
      • --None--
      • OPEN
      • REJECTED
      • RESOLVED
      Related Issue Severity
      • --None--
      • CRITICAL
      • HIGH
      • INFORMATIONAL
      • LOW
      • MEDIUM
      Has Public Exploit Filter on vulnerability findings for vulnerabilities with an available exploit: (true/false).
      Project ID Filter for vulnerability findings with strings that you enter for the given projects.
      Has Fix Filter on vulnerability findings for vulnerabilities with an available fix (true/false).
      Resource Filter on a resource you enter.
      Resource Has Admin Privileges Filter for vulnerability findings for assets that have admin privileges (true/false).
      Subscription Import findings from the following strings for external subscriptions: (AWS Account, Azure Subscription, GCP Project, and OCI Compartment). You can specify multiple values in an array. If you do not provide a value, all subscriptions are returned.
      Has CISA KEV Exploit Filter for vulnerability findings for vulnerabilities with an available CISA KEV exploit (true/false).
      Resource Has High Privileges Filter for vulnerability findings for assets that have high privileges (true/false).
      Validated In Runtime
      • --None--
      • Yes- Select Yes to pull in data for resources that have this flag set to Yes in the Runtime field. In Wiz console, the 'Validated in Runtime' status for a finding typically persists for a 48-hour period from the last time the vulnerable package was detected in memory.
      • No. Do not pull data for these resources.
      Resource Has Wide Internet Exposure Filter for vulnerability findings for assets that have high internet exposure (true/false).
      Resource Has Limited Internet Exposure Filter for vulnerability findings for assets that have low internet exposure (true/false).
      First Seen At (After) Filter by assets seen starting with a date you select.
      Resolved At (After) Filter by assets with vulnerabilities that have been resolved starting with a date you select.
      Updated At (After) Filter by assets that have been updated starting with a date you select.
    5. Select Save and test.
      If the credentials have been saved and validated successfully a message is displayed. You can select filtering for another integration import.