Wiz for Microsoft Sentinel

Solution: Wiz

Wiz Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Solutions Index


Attribute Value
Publisher Wiz
Support Tier Partner
Support Link https://support.wiz.io/
Categories Security - Cloud Security,Security - Threat Protection
Version 3.0.2
Author Wiz - support@wiz.io
First Published 2023-06-20
Last Updated 2026-08-03
Solution Folder Wiz
Marketplace Azure Marketplace · Popularity: 🟢 High (83%)

The Wiz solution for Microsoft Sentinel lets Wiz push Wiz Issues, Wiz Detections, and Wiz Audit Logs into Microsoft Sentinel in real time. Wiz sends data to a Data Collection Endpoint (DCE) using the Wiz service principal; this solution grants that service principal the least-privilege RBAC it needs, and Wiz then creates the data collection rule and tables. There is no Azure Function to host and no workspace shared keys to manage.

Underlying Microsoft Technologies used:

This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:

a. Data Collection Rules and the Logs Ingestion API

Contents

Data Connectors

This solution provides 1 data connector(s) (plus 1 discovered⚠️):

🔍 Discovered: This item was discovered by scanning the solution folder but is not listed in the Solution JSON file.

🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Tables Used

This solution uses 9 table(s):

Table Used By Connectors Used By Content
WizAuditLogsV2_CL 🔶 Wiz -
WizAuditLogsV3_CL Wiz for Microsoft Sentinel -
WizAuditLogs_CL 🔶 Wiz -
WizDetectionsV3_CL Wiz for Microsoft Sentinel -
WizIssuesV2_CL 🔶 Wiz -
WizIssuesV3_CL Wiz for Microsoft Sentinel Workbooks
WizIssues_CL 🔶 Wiz -
WizVulnerabilitiesV2_CL 🔶 Wiz -
WizVulnerabilities_CL 🔶 Wiz -

🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Content Items

This solution includes 1 content item(s):

Content Type Count
Workbooks 1

Workbooks

Name Tables Used
WizFindings WizIssuesV3_CL

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.0.2 18-08-2026 Updated the Connector STEP 1 instructions to use a tenant-specific Application (client) ID, so setup works for any Wiz tenant. Clarified that the command output is the service principal object ID.
3.0.1 26-06-2026 Added a new push-based Connector (DCR + RBAC grant): Wiz pushes data to WizIssuesV3_CL, WizDetectionsV3_CL, and WizAuditLogsV3_CL (Issues, Detections, Audit Logs), with no Azure Function to host. Workbook updated to the new tables and columns. The legacy Azure Function connector remains available for existing deployments.
3.0.0 15-07-2024 Updated the queries on the Workbook and Connector to match with the new table names we offer
2.0.0 07-09-2023 Updated Workbook query in Maintemplate

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Solutions Index