cspm.wiz
Introduction
The tags beginning with cspm.wiz
identify events generated by Wiz.
Valid tags and data tables
The full tag must have 4 levels. The first two are fixed as cspm.wiz
. The third level identifies the type of events sent, and the fourth level indicates the event subtype.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Tag | Data table |
---|---|
|
|
|
|
|
|
|
|
|
|
|
|
For more information, read more About Devo tags.
How to send data to Devo
To send logs to these tables, Devo provides a collector that you can download and use to send the required events to your Devo domain. You can learn how to use it in this article.
Table structure
These are the fields displayed in these tables:
cspm.wiz.audit.default
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
id |
|
|
action |
|
|
request_id |
|
|
status |
|
|
timestamp |
|
|
action_client_id |
|
|
action_groups |
|
|
action_name |
|
|
action_products |
|
|
action_role |
|
|
action_scopes |
|
|
action_user_email |
|
|
action_user_id |
|
|
action_userpool_id |
|
|
user_agent |
|
|
source_ip |
|
|
source_ipv4 |
|
|
source_ipv6 |
|
|
service_account_id |
|
|
service_account_name |
|
|
user |
|
|
at_devo_pulling_id |
|
|
is_flattened |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
cspm.wiz.cloud_configuration.default
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
id |
|
|
target_external_id |
|
|
target_object_provider_unique_id |
|
|
first_seen_at |
|
|
severity |
|
|
result |
|
|
status |
|
|
remediation |
|
|
resource_id |
|
|
resource_provider_id |
|
|
resource_name |
|
|
resource_native_type |
|
|
resource_type |
|
|
resource_region |
|
|
resource_subscription |
|
|
resource_projects |
|
|
resource_tags |
|
|
rule_id |
|
|
rule_graph_id |
|
|
rule_name |
|
|
rule_description |
|
|
rule_remediation_instructions |
|
|
rule_function_as_control |
|
|
security_sub_categories |
|
|
ignore_rules |
|
|
at_devo_pulling_id |
|
|
is_flattened |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
cspm.wiz.cloud_event.default
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
id |
|
|
name |
|
|
kind |
|
|
origin |
|
|
severity |
|
|
external_id |
|
|
external_name |
|
|
cloud_platform |
|
|
timestamp |
|
|
cloud_native_service |
|
|
category |
|
|
actor_id |
|
|
actor_external_id |
|
|
actor_provider_unique_id |
|
|
actor_type |
|
|
actor_cloud_account |
|
|
actor_is_external_cloud_account |
|
|
actor_friendly_name |
|
|
actor_name |
|
|
actor_email |
|
|
actor_user_agent |
|
|
actor_ip |
|
|
actor_ipv4 |
|
|
actor_ipv6 |
|
|
actor_ip_meta_country |
|
|
actor_ip_meta_country_code |
|
|
actor_ip_meta_city |
|
|
actor_ip_meta_reputation |
|
|
actor_ip_meta_reputation_source |
|
|
actor_ip_meta_reputation_description |
|
|
is_foreign_actor_ip |
|
|
subject_resource_id |
|
|
subject_resource_external_id |
|
|
subject_resource_provider_unique_id |
|
|
subject_resource_type |
|
|
subject_resource_native_type |
|
|
subject_resource_name |
|
|
subject_resource_hostname |
|
|
subject_resource_cloud_account_id |
|
|
subject_resource_cloud_account_external_id |
|
|
subject_resource_cloud_account_name |
|
|
subject_resource_cloud_account_cloud_provider |
|
|
subject_resource_cloud_account_linked_projects |
|
|
subject_resource_region |
|
|
subject_resource_tags |
|
|
subject_resource_open_to_all_internet |
|
|
subject_resource_has_sensitive_data |
|
|
subject_resource_kubernetes_cluster_id |
|
|
subject_resource_kubernetes_cluster_name |
|
|
subject_resource_kubernetes_cluster_type |
|
|
subject_resource_kubernetes_namespace_id |
|
|
subject_resource_kubernetes_namespace_name |
|
|
subject_resource_kubernetes_namespace_type |
|
|
subject_resource_kubernetes_flavor |
|
|
subject_resource_container_service |
|
|
cloud_provider_url |
|
|
file_path |
|
|
hash |
|
|
at_devo_pulling_id |
|
|
is_flattened |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
cspm.wiz.issues.default
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
|
|
|
|
hostname |
|
|
|
|
version |
| split(tag, '.', 4) | tag |
|
format |
| split(tag, '.', 5) | tag |
|
id |
|
|
|
|
control_id |
|
|
|
|
control_name |
|
|
|
|
query_relationships |
|
|
|
|
query_select |
|
|
|
|
query_type |
|
|
|
|
security_sub_categories |
|
|
|
|
created_at |
|
|
|
|
updated_at |
|
|
|
|
projects |
|
|
|
|
status |
|
|
|
|
severity |
|
|
|
|
entity_id |
|
|
|
|
entity_name |
|
|
|
|
entity_type |
|
|
|
|
entity_snapshot_id |
|
|
|
|
entity_snapshot_type |
|
|
|
|
entity_snapshot_nativeType |
|
|
|
|
entity_snapshot_name |
|
|
|
|
entity_snapshot_subscription_id |
|
|
|
|
entity_snapshot_subscription_external_id |
|
|
|
|
entity_snapshot_subscription_name |
|
|
|
|
entity_snapshot_resource_group_id |
|
|
|
|
entity_snapshot_resource_group_externalId |
|
|
|
|
entity_snapshot_region |
|
|
|
|
entity_snapshot_cloud_platform |
|
|
|
|
entity_snapshot_cloud_provider_url |
|
|
|
|
entity_snapshot_provider_id |
|
|
|
|
entity_snapshot_status |
|
|
|
|
entity_snapshot_aws_autoscaling_group_name |
|
|
|
|
entity_snapshot_aws_ec2_fleet_id |
|
|
|
|
entity_snapshot_aws_ec2launchtemplate_id |
|
|
|
|
entity_snapshot_aws_ec2launchtemplate_version |
|
|
|
|
entity_snapshot_eks_cluster_name |
|
|
|
|
entity_snapshot_eks_nodegroup_name |
|
|
|
|
entity_snapshot_k8s_io_cluster_autoscaler_enabled |
|
|
|
|
entity_snapshot_k8s_io_cluster_autoscaler_node_template_label_pulumi_project |
|
|
|
|
entity_snapshot_k8s_io_cluster_autoscaler_node_template_label_pulumi_stack |
|
|
|
|
entity_snapshot_k8s_io_cluster_autoscaler_node_template_label_topology_kubernetes_io_zone |
|
|
|
|
entity_snapshot_k8s_io_cluster_autoscaler_node_template_label_wiz |
|
|
|
|
entity_snapshot_k8s_io_cluster_autoscaler_node_template_label_wiz_csi_ready |
|
|
|
|
entity_snapshot_k8s_io_cluster_autoscaler_node_template_label_wiz_io_cluster_name |
|
|
|
|
entity_snapshot_k8s_io_cluster_autoscaler_node_template_label_wiz_io_disk_size |
|
|
|
|
entity_snapshot_k8s_io_cluster_autoscaler_node_template_label_wiz_io_node_group_type |
|
|
|
|
entity_snapshot_k8s_io_cluster_autoscaler_node_template_label_wiz_outpost_id |
|
|
|
|
entity_snapshot_k8s_io_cluster_autoscaler_node_template_label_wiz_dc |
|
|
|
|
entity_snapshot_k8s_io_cluster_autoscaler_node_template_label_wiz_region |
|
|
|
|
entity_snapshot_k8s_io_cluster_autoscaler_wiz_orchestrator_eks_cluster_go_uxyracz1 |
|
|
|
|
entity_snapshot_kubernetes_io_cluster_wiz_orchestrator_eks_cluster_go_uxyracz1 |
|
|
|
|
entity_snapshot_pulumi_project |
|
|
|
|
entity_snapshot_pulumi_stack |
|
|
|
|
entity_snapshot_topology_ebs_csi_aws_com_zone |
|
|
|
|
entity_snapshot_wiz |
|
|
|
|
entity_snapshot_wiz_dc |
|
|
|
|
entity_snapshot_wiz_region |
|
|
|
|
entity_snapshot_wiz_outpost_id |
|
|
|
|
note |
|
|
|
|
service_ticket |
|
|
|
|
service_tickets |
|
|
|
|
at_devo_pulling_id |
|
|
|
|
is_flattened |
|
|
|
|
hostchain |
|
|
| ✓ |
tag |
|
|
| ✓ |
rawMessage |
|
|
| ✓ |
cspm.wiz.system_activity.default
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
id |
|
|
name |
|
|
trigger_type |
|
|
triggered_by_id |
|
|
created_at |
|
|
started_at |
|
|
ended_at |
|
|
status |
|
|
status_info |
|
|
summary |
|
|
group_id |
|
|
at_devo_pulling_id |
|
|
is_flattened |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
cspm.wiz.vulnerabilities.default
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
id |
|
|
portal_url |
|
|
name |
|
|
cve_description |
|
|
cvss_severity |
|
|
score |
|
|
exploitability_score |
|
|
impact_score |
|
|
data_source_name |
|
|
has_exploit |
|
|
has_cisa_kev_exploit |
|
|
status |
|
|
vendor_severity |
|
|
first_detected_at |
|
|
last_detected_at |
|
|
resolved_at |
|
|
description |
|
|
remediation |
|
|
detailed_name |
|
|
version |
|
|
fixed_version |
|
|
detection_method |
|
|
link |
|
|
location_path |
|
|
resolution_reason |
|
|
epss_severity |
|
|
epss_percentile |
|
|
epss_probability |
|
|
validated_in_runtime |
|
|
layer_id |
|
|
layer_details |
|
|
layer_is_base_layer |
|
|
projects |
|
|
ignore_rules |
|
|
asset_id |
|
|
asset_type |
|
|
asset_name |
|
|
asset_region |
| ✓ |
asset_provider_unique_id |
| ✓ |
asset_cloud_provider_url |
| ✓ |