Set filtering for the Wiz Host Vulnerabilities Integration
Set the filtering values to import the host vulnerability data that you want.
Before you begin
Role required: sn_vul_wiz.configure_integration
Procedure
Navigate to All > Wiz Vulnerability Integration > Administration > Configuration.
If not already selected, select the Host Vulnerabilities Configuration tab.
Fill in the fields.
These fields that are displayed provide you with filters to import basic host vulnerability data. Refer to the following tables for more information.
| Field | Description |
|---|---|
| First | Pagination. Enter a value. You might prefer to start with 1000. |
| Severity | Finding severity. None is the default. If selected, this indicates you don’t want to import any data for this field. You can specify multiple values:- NONE - Return assets with no available severity values. - LOW - MEDIUM - HIGH - CRITICAL |
| Resource Status | Return only vulnerability findings for assets with these statuses. You can specify multiple values:- None \(default\) - If selected, this indicates you do not want to import any data for this field. - Active - Error - Inactive |
To view more filtering options, select the **Advanced** check box.
Select the Advanced check box to view more filtering options.
For most fields, you can specify multiple values.
--None--is the (default). If--None--remains selected for a field, no data is imported for this field.If displayed select the lock icons (
An closed padlock icon that indicates the field is locked and not editable.\) and \(\[Omitted image "dlp-unlock-icon.png"\] Alt text: An opened padlock icon that indicates the field is unlocked and editable.\) to edit and lock your edits.
| Field | Description |
|---|---|
| Detection Method | Filter on vulnerability findings found by these detection methods:- --None-- - DEFAULT\_PACKAGE - FILE\_PATH - INSTALLED\_PROGRAM - INSTALLED\_PROGRAM\_BY\_SERVICE - LIBRARY - OS - PACKAGE |
| Vulnerability | Filter on vulnerability findings with matching external ID\(s\) that you enter, for example, CVE-1234-5678,CVE-9110-26117. |
| Status | Filter by finding status:- --None-- - OPEN - REJECTED - RESOLVED |
| Related Issue Severity | - --None-- - CRITICAL - HIGH - INFORMATIONAL - LOW - MEDIUM |
| Has Public Exploit | Filter on vulnerability findings for vulnerabilities with an available exploit: \(true/false\). |
| Project ID | Filter for vulnerability findings with strings that you enter for the given projects. |
| Has Fix | Filter on vulnerability findings for vulnerabilities with an available fix \(true/false\). |
| Resource | Filter on a resource you enter. |
| Resource Has Admin Privileges | Filter for vulnerability findings for assets that have admin privileges \(true/false\). |
| Subscription | Import findings from the following strings for external subscriptions: \(AWS Account, Azure Subscription, GCP Project, and OCI Compartment\). You can specify multiple values in an array. If you do not provide a value, all subscriptions are returned. |
| Has CISA KEV Exploit | Filter for vulnerability findings for vulnerabilities with an available CISA KEV exploit \(true/false\). |
| Resource Has High Privileges | Filter for vulnerability findings for assets that have high privileges \(true/false\). |
| Validated In Runtime |
|
| Resource Has Wide Internet Exposure | Filter for vulnerability findings for assets that have high internet exposure \(true/false\). |
| Resource Has Limited Internet Exposure | Filter for vulnerability findings for assets that have low internet exposure \(true/false\). |
| First Seen At \(After\) | Filter by assets seen starting with a date you select. |
| Resolved At \(After\) | Filter by assets with vulnerabilities that have been resolved starting with a date you select. |
| Updated At \(After\) | Filter by assets that have been updated starting with a date you select. |
Select Save and test.
If the credentials have been saved and validated successfully a message is displayed. You can select filtering for another integration import.