Wiz
Last updated
Last updated
To configure the Wiz Security integration, follow these steps:
In the the Wiz Application, Search "Service Accounts"
Click "Add Service Account"
Enter a name, Choose "Custom Integration (GraphQL API)" from the Type drop down.
Select Projects you want Gomboc to have access to.
Select the following scopes:
Read graph resource
Issues
Issue Comments
Integratons
Automation Rules
Read report
Read cloud configuration rules, list cloud configuration rules
Detections
Issue Status
Comments
Click "Add Service Account" and collect Client ID and Client Secret. You will need them in future steps.
In Wiz click your profile icon and "Tenant Info"
Collect API Endpoint URL and Authentication URL for future steps
Within the Gomboc portal, create an access token, either a personal or organization API token will work. Once the token is created, copy it to your clipboard.
Go to Settings > Integrations > Wiz
Insert the Gomboc Token from step 3. Wiz Client ID, Wiz Client Secret from Service Account setup. Wiz API URL, Wiz Auth URL from step 2. Click "Integrate"
Once the integration is complete you will receive an Access token you will need to use to create the webhook on Wiz
Back on the Wiz Application, search "Integrations"
Click "Add Integration"
Search "Webhook"
Enter a name. Under URL enter "https://cspm.prod.gcp.gomboc.ai/api/v1/observations/wiz"
Select All projects you want to integrate with, It should be the same as the Service Account
Under Authentication select Token, Enter the Token received after creating the integraion in Gomboc portal, click "Add Integration"
Search "Automation Rules"
Click "Add Rule"
Enter name "Issue Webhook"
Select same projects from Service Account setup
Under "When" select Issue
Under "IF" click Add Filter, select "Severity", then select all the options.
Under "THEN" click add Action and select "POST a Webhook" for the created Integration. Click "Continue", then "Add Action"
Click "Add Rule"
Repeat Steps 2 - 8 changing to "Cloud Configuration Finding" and "Detection" under "WHEN" in step 5