Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Set filtering for the Wiz Host Vulnerabilities Integration

Set the filtering values to import the host vulnerability data that you want.

Before you begin

Role required: sn_vul_wiz.configure_integration

Procedure

  1. Navigate to All > Wiz Vulnerability Integration > Administration > Configuration.

  2. If not already selected, select the Host Vulnerabilities Configuration tab.

  3. Fill in the fields.

    These fields that are displayed provide you with filters to import basic host vulnerability data. Refer to the following tables for more information.

FieldDescription
FirstPagination. Enter a value. You might prefer to start with 1000.
SeverityFinding severity. None is the default. If selected, this indicates you don’t want to import any data for this field. You can specify multiple values:- NONE - Return assets with no available severity values. - LOW - MEDIUM - HIGH - CRITICAL
Resource StatusReturn only vulnerability findings for assets with these statuses. You can specify multiple values:- None \(default\) - If selected, this indicates you do not want to import any data for this field. - Active - Error - Inactive
To view more filtering options, select the **Advanced** check box.
  1. Select the Advanced check box to view more filtering options.

    For most fields, you can specify multiple values. --None-- is the (default). If --None-- remains selected for a field, no data is imported for this field.

    If displayed select the lock icons (

Image omitted: dlp-lock-icon.png
An closed padlock icon that indicates the field is locked and not editable.\) and \(\[Omitted image "dlp-unlock-icon.png"\] Alt text: An opened padlock icon that indicates the field is unlocked and editable.\) to edit and lock your edits.
FieldDescription
Detection MethodFilter on vulnerability findings found by these detection methods:- --None-- - DEFAULT\_PACKAGE - FILE\_PATH - INSTALLED\_PROGRAM - INSTALLED\_PROGRAM\_BY\_SERVICE - LIBRARY - OS - PACKAGE
VulnerabilityFilter on vulnerability findings with matching external ID\(s\) that you enter, for example, CVE-1234-5678,CVE-9110-26117.
StatusFilter by finding status:- --None-- - OPEN - REJECTED - RESOLVED
Related Issue Severity- --None-- - CRITICAL - HIGH - INFORMATIONAL - LOW - MEDIUM
Has Public ExploitFilter on vulnerability findings for vulnerabilities with an available exploit: \(true/false\).
Project IDFilter for vulnerability findings with strings that you enter for the given projects.
Has FixFilter on vulnerability findings for vulnerabilities with an available fix \(true/false\).
ResourceFilter on a resource you enter.
Resource Has Admin PrivilegesFilter for vulnerability findings for assets that have admin privileges \(true/false\).
SubscriptionImport findings from the following strings for external subscriptions: \(AWS Account, Azure Subscription, GCP Project, and OCI Compartment\). You can specify multiple values in an array. If you do not provide a value, all subscriptions are returned.
Has CISA KEV ExploitFilter for vulnerability findings for vulnerabilities with an available CISA KEV exploit \(true/false\).
Resource Has High PrivilegesFilter for vulnerability findings for assets that have high privileges \(true/false\).
Validated In Runtime
  • --None--
  • Yes- Select Yes to pull in data for resources that have this flag set to Yes in the Runtime field. In Wiz console, the 'Validated in Runtime' status for a finding typically persists for a 48-hour period from the last time the vulnerable package was detected in memory.
  • No. Do not pull data for these resources.
Resource Has Wide Internet ExposureFilter for vulnerability findings for assets that have high internet exposure \(true/false\).
Resource Has Limited Internet ExposureFilter for vulnerability findings for assets that have low internet exposure \(true/false\).
First Seen At \(After\)Filter by assets seen starting with a date you select.
Resolved At \(After\)Filter by assets with vulnerabilities that have been resolved starting with a date you select.
Updated At \(After\)Filter by assets that have been updated starting with a date you select.
  1. Select Save and test.

    If the credentials have been saved and validated successfully a message is displayed. You can select filtering for another integration import.