Wiz Webhook (Beta)

Panther supports receiving logs from Wiz webhooks

Overview

The Wiz webhook integration is in open beta starting with Panther version 1.116, and is available to all customers. Please share any bug reports and feature requests with your Panther support team.

Panther can receive real-time webhook notifications from Wiz containing Issues, Threats, and Detections events. This integration provides immediate visibility into security findings across your cloud infrastructure, enabling fast incident response.

To ingest different types of Wiz logs, you can additionally or instead use the Wiz API integration. Note that the Wiz.IssuesWebhook events available through this integration and the Wiz.Issues events available through the Wiz API integration differ slightly.

How to onboard Wiz webhook logs to Panther

Prerequisites

  • To set up this integration, you must have access to a Wiz tenant and permission to create a webhook.

  • To receive Threats and Detections events, you must have a subscription to Wiz Defend.

Step 1: Create a new Wiz webhook log source in Panther

  1. In the left-hand navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search for "Wiz Webhook," then click its tile.

  4. In the upper-right corner of the slide-out panel, click Start Setup.

    A page in the Panther console with the trail Configure > Log Sources > Add New Source is shown, with a slide-out panel expanded with the title Wiz. An arrow is drawn to a "Start Setup" button.
  5. Follow Panther's instructions for configuring an HTTP Source, beginning at Step 5.

Step 2: Configure webhook notifications in Wiz

  1. In your Wiz console, navigate to Settings > Integrations.

  2. Click Add Integration.

  3. Under SIEM & Automation Tools, click Webhook.

  4. On the New Integration page, fill in the fields:

    • Name: provide a descriptive name for the webhook, e.g., Panther Integration.

    • Project Scope: select the scopes you'd like to include.

    • URL: enter the HTTP Source URL you generated in Panther.

    • Authentication: select the type of authentication you used in Panther in Step 1, and provide the associated credentials.

  5. Click Add Integration.

Panther-managed detections

See Panther-managed rules for Wiz in the panther-analysis GitHub repository.

Supported log types

Wiz.IssuesWebhook

The Issues log records key events in Wiz related to issues, such as vulnerability findings and security incidents. It is used to track, manage, and remediate security vulnerabilities and incidents.

Wiz.Threats

The Threats log records webhook notifications for threat detection events. This helps track active threats, malicious activities, and security incidents across your cloud infrastructure.

Wiz.Detections

The Detections log captures webhook notifications for security detection findings. This includes alerts from security rules, anomaly detection, and behavioral analysis.

Last updated

Was this helpful?