Set filtering for the Wiz Host Vulnerabilities Integration
Set the filtering values to import the host vulnerability data that you want.
Before you begin
Role required: sn_vul_wiz.configure_integration
Procedure
- Navigate to All > Wiz Vulnerability Integration > Administration > Configuration.
- If not already selected, select the Host Vulnerabilities Configuration tab.
-
Fill in the fields.
These fields that are displayed provide you with filters to import basic host vulnerability data. Refer to the following tables for more information.
Field Description First Pagination. Enter a value. You might prefer to start with 1000. Severity Finding severity. None is the default. If selected, this indicates you don’t want to import any data for this field. You can specify multiple values: - NONE - Return assets with no available severity values.
- LOW
- MEDIUM
- HIGH
- CRITICAL
Resource Status Return only vulnerability findings for assets with these statuses. You can specify multiple values: - None (default) - If selected, this indicates you do not want to import any data for this field.
- Active
- Error
- Inactive
To view more filtering options, select the Advanced check box.
-
Select the Advanced check box to view more filtering options.
For most fields, you can specify multiple values. --None-- is the (default). If --None-- remains selected for a field, no data is imported for this field.
If displayed select the lock icons (
) and (
) to edit and lock your edits.
Field Description Detection Method Filter on vulnerability findings found by these detection methods: - --None--
- DEFAULT_PACKAGE
- FILE_PATH
- INSTALLED_PROGRAM
- INSTALLED_PROGRAM_BY_SERVICE
- LIBRARY
- OS
- PACKAGE
Vulnerability Filter on vulnerability findings with matching external ID(s) that you enter, for example, CVE-1234-5678,CVE-9110-26117. Status Filter by finding status: - --None--
- OPEN
- REJECTED
- RESOLVED
Related Issue Severity - --None--
- CRITICAL
- HIGH
- INFORMATIONAL
- LOW
- MEDIUM
Has Public Exploit Filter on vulnerability findings for vulnerabilities with an available exploit: (true/false). Project ID Filter for vulnerability findings with strings that you enter for the given projects. Has Fix Filter on vulnerability findings for vulnerabilities with an available fix (true/false). Resource Filter on a resource you enter. Resource Has Admin Privileges Filter for vulnerability findings for assets that have admin privileges (true/false). Subscription Import findings from the following strings for external subscriptions: (AWS Account, Azure Subscription, GCP Project, and OCI Compartment). You can specify multiple values in an array. If you do not provide a value, all subscriptions are returned. Has CISA KEV Exploit Filter for vulnerability findings for vulnerabilities with an available CISA KEV exploit (true/false). Resource Has High Privileges Filter for vulnerability findings for assets that have high privileges (true/false). Validated In Runtime - --None--
- Yes- Select Yes to pull in data for resources that have this flag set to Yes in the Runtime field. In Wiz console, the 'Validated in Runtime' status for a finding typically persists for a 48-hour period from the last time the vulnerable package was detected in memory.
- No. Do not pull data for these resources.
Resource Has Wide Internet Exposure Filter for vulnerability findings for assets that have high internet exposure (true/false). Resource Has Limited Internet Exposure Filter for vulnerability findings for assets that have low internet exposure (true/false). First Seen At (After) Filter by assets seen starting with a date you select. Resolved At (After) Filter by assets with vulnerabilities that have been resolved starting with a date you select. Updated At (After) Filter by assets that have been updated starting with a date you select. -
Select Save and test.
If the credentials have been saved and validated successfully a message is displayed. You can select filtering for another integration import.