This guide outlines how to integrate Wiz with Red Canary’s MDR for Cloud offering. Wiz is a cloud-native security platform that provides comprehensive posture analysis and threat detection across your cloud environments. The integration combines Wiz detection capabilities with Red Canary’s expert investigation, enabling our teams to investigate Wiz-generated alerts and enrich Red Canary investigations with valuable Wiz risk context. For more information on how Red Canary ingests data from Wiz, see the FAQ.
Prerequisites
Before you start the Wiz integration, please make sure the following requirements are met:
You have an active Red Canary MDR Cloud subscription
You are sending control plane telemetry to Red Canary through the AWS, Azure, or GCP integrations
You have the following Wiz licenses:
Wiz Advanced Cloud License: This is the minimum required license and must include Threat Detection Issues, Toxic Combinations, and Cloud Config Findings.
Wiz Defend Ingestion Add-on: This add-on enables additional features. To ingest identity threats and additional detections into Red Canary, you must have the Wiz Defend add-on and at least one integrated identity provider (Okta, Entra ID, or Google Workspace).
You consent to the required permissions (configured in Step 2). For more details, see the FAQ.
1 Red Canary | Add the Integration
From your Red Canary homepage, go to the Integrations page, then click Add Integration.

On the Add integration dialog, search for the Wiz integration, then click Configure.

On the Red Canary configuration page, enter a name for the integration.

2 Red Canary | Record the API and Oath Tokens
In Step 2: Record the API and OAuth tokens, copy the Wiz OAuth Client ID and Wiz OAuth Client Secret. You’ll need this in a later step.

3 Red Canary | Customize How This Data Is Retained
[OPTIONAL] If you’re subscribed to the Red Canary Security Data Lake managed storage solution, you can choose to copy the telemetry generated by the integration to long-term storage for later query or retrieval.
Check the Store in the Security Data Lake box.

Enter your desired data retention period in days. The maximum is 1095 days (three years).
4 Wiz | Connect Red Canary to Wiz
In Wiz, go to the Connect to Wiz page:
Under Security & Identity, select Red Canary.
On the Connection page:
Enter a Base URL. The default value is
https://api.redcanary.com.Paste the Client ID and Client Secret you copied from the Red Canary integation.
Enter an Application ID such as "wiz-redcanary." Make sure to use only lower case letters and no spaces.
Click Continue.
On the Details page:
Enter a display name.
(Optional) Enable Filter out on-prem events if your instance of Red Canary covers on-prem workloads that Wiz cannot scan.
Click Finish.
5 Red Canary | Activate the Integration
After you’ve completed the configuration, click Save to activate the integration.
The Wiz integration is now live!
Wiz data should appear in Red Canary within 5 minutes, provided it is a supported data type that meets our filtering criteria. For additional details, see the FAQ.
6 Red Canary | Modify the Integration
After the Wiz integration is active, you can make the following modifications to the configuration:
Update the API configuration used by the integration
Adjust the Security Data Lake retention period
Decommission the integration
To modify the configuration:
From your Red Canary homepage, go to the Integrations page, then click on the name of the integration you want to modify.

After you’ve finished editing the configuration, click Save to apply your changes.
Deleting the Integration
To delete the integration from Red Canary, click the
button, then click OK to confirm.
Important
Deleting the integration will prevent any new alerts from being sent to Red Canary. While existing threat data will remain, all processed alerts will be permanently deleted, and this action cannot be undone.
For this reason, we recommend deactivating the integration instead, which will retain all previously processed alerts but stop further ingestion. You can reactivate the integration at any time.
FAQ
What are the required permissions for the Wiz integration?
The table below details all required permissions and explains why Red Canary requires each one.
Category | Permission | Justification |
|---|---|---|
Cloud Events | Read (read:cloud_events_cloud) | Used to resolve triggering event data within detections for investigative context |
Detections | Read (read:detections) | Used to retrieve threat detections, the primary data source for Wiz alert ingestion |
Issues | Read/list (read:issues) | Used to retrieve issues associated with detections for investigative context |
Read/list (read:threat_issues) | Used to retrieve threat detection issues linked to detections for display in the Red Canary portal | |
Resources | Read (read:resources) | Used to retrieve cloud accounts for scoping detection queries and to enrich cloud resource data |
Which types of Wiz data does Red Canary ingest?
Red Canary is capable of ingesting the following types of alert data, each serving specific purposes for threat detection and investigation:
Alerts processed through Red Canary's investigative workflows
These alerts undergo comprehensive analysis through Red Canary's investigative workflows. They enable Red Canary to identify and address potential threats effectively.
Detections: Detections represent findings generated by Threat Detection Rules when analyzing cloud events, logs, or runtime activity. These high-fidelity alerts are designed to identify suspicious and unusual activity in cloud environments. Wiz automatically groups related Detections into a broader Threat for better context.
Threat Detection Issues: Generated by Threat Detection Rules, these Issues arise from the evaluation of cloud events affecting individual resources. They indicate the detection of specific suspicious activities within a cloud environment. Red Canary fetches the associated Threat Detection Issue for each Detection to provide additional investigative context, including source rules, affected entities, and project information.
Why is Wiz data not appearing in Red Canary?
If you're not seeing Wiz data in Red Canary, it may be due to one or more of the following reasons:
Non-essential Alert Data: Red Canary only ingests alerts categorized as Medium, High, or Critical. Any Low-level alerts sent to Red Canary will be filtered out and will not appear in the portal. For details, see the FAQ What are the required permissions for the Wiz integration? above.
Unsupported Data Types: Red Canary only ingests Detections and Threat Detection Issues from Wiz. Other Wiz data types, such as Toxic Combination Issues or Cloud Configuration Findings, are not ingested and will not be visible in the portal.
Incorrect Permissions Configuration: Red Canary requires certain permissions, which are configured in Step 2 of the setup process. If any of these permissions are missing or misconfigured, it could prevent the ingestion of Wiz data into Red Canary. For details, see the FAQ What are the required permissions for the Wiz integration? above.