Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Connector ID | WizSentinel |
| Publisher | Wiz |
| Used in Solutions | Wiz |
| Collection Method | Azure Function |
| Connector Definition Files | WizSentinel.json |
| Ingestion API | Log Ingestion API | HTTP Data Collector API — Sibling ARM template declares DCR / Log Ingestion API resources; Connector definition requires workspace key (SharedKey pattern) |
| Microsoft Learn | View on Learn |
The Wiz integration pushes Wiz Issues, Detections, and Audit Logs into Microsoft Sentinel in real time. Wiz sends data to a Data Collection Endpoint using the Wiz service principal, so there is no Azure Function to host and no shared keys to manage. This connector grants that service principal the least-privilege RBAC it needs; Wiz then creates the data collection rule and tables and begins pushing once you configure the integration in the Wiz portal.
This connector ingests data into the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
WizAuditLogsV3_CL |
✗ | ✓ | ✗ |
WizDetectionsV3_CL |
✓ | ✓ | ✓ |
WizIssuesV3_CL |
✓ | ✓ | ✓ |
💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.
Resource Provider Permissions:
Custom Permissions:
⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.
1. STEP 1 - Get the Wiz service principal object ID
ARM cannot resolve a Microsoft Entra object, so you supply the Wiz service principal object ID. This app registration is unique to your Wiz tenant — find your Application (client) ID on the Microsoft Sentinel integration setup screen in Wiz (Settings > Integrations > Add > Microsoft Sentinel), then substitute it for WIZ_APP_ID_HERE below. In Azure Cloud Shell (no local install required; creating the service principal needs permission to register enterprise applications in Microsoft Entra ID) run the line below. It prints the service principal object ID — copy that value into the deployment parameter. It creates the service principal first if it does not yet exist in your tenant:
WIZ_APP_ID="WIZ_APP_ID_HERE" # Application (client) ID from the Wiz Microsoft Sentinel integration setup screen
az ad sp show --id "$WIZ_APP_ID" --query id -o tsv 2>/dev/null \
|| az ad sp create --id "$WIZ_APP_ID" --query id -o tsv
If the command fails, rerun it without 2>/dev/null to see the full error.
2. STEP 2 - Grant Wiz the RBAC
Deploy the custom role and assignment into the resource group that hosts this workspace. Paste the object ID from Step 1 (and, optionally, a Data Collection Endpoint resource ID).
Click Deploy the Wiz RBAC role:
Select the Subscription and the Resource group that hosts this workspace.
Enter wizPrincipalObjectId (from Step 1); optionally dataCollectionEndpointId.
Review + create.
WorkspaceResourceIdNote: The value above is dynamically provided when these instructions are presented within Microsoft Sentinel.
3. STEP 3 - Configure the integration in Wiz
In Wiz, go to Settings > Integrations > Add > Microsoft Sentinel. Paste your Tenant ID, Workspace Resource ID, and Data Collection Endpoint Resource ID, tick Deployment completed, and save. Wiz then creates the data collection rule and tables and begins pushing Issues, Detections, and Audit Logs into this workspace.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊