Configure Service Graph Connector for Wiz using SGC Central
Set up scheduled import jobs to pull in data from a Wiz project into your Configuration Management Database (CMDB).
Before you begin
- Install Service Graph Connector for Wiz version 1.3.0 or later from the ServiceNow Store. For ServiceNow Store installation steps, see Install a ServiceNow Store application.
You must obtain the OAuth credentials associated with the Wiz service account and make a note of the following details:
- Client ID
- Client secret
- OAuth token URL
- Connection URL For more information, see Set up the Wiz environment.
You must have the following permissions for the Wiz service account:
- read:resources
- read:projects
Role required: The following table shows the roles required for each stage of the playbook.
| Stage | Role |
|---|---|
| Prerequisites | admin |
| Setup | cmdb_inst_admin or admin |
About this task
The playbook experience for onboarding connectors is activated with SGC Central in the Service Graph Workspace or CMDB Workspace. To configure the SGC Central application, see Configuring SGC Central and for more information on how to interact with a playbook, see Interact with Playbook.
Procedure
Use one of the following methods to open SGC Central:
- Navigate to Workspaces > Service Graph Workspace, and from the left navigation panel, select the Ingestion icon
No alternative text supplied
to open the SGC Central view. - Navigate to Workspaces > CMDB Workspace > SGC Central. 2. On the Overview page, select Create connection.
**Tip:** Alternatively, you can select **Create connection** on the All connections page.
On the Create connection window, select the Wiz connector type, and then select Configure connection.
A default connection, SG-Wiz, for Wiz is available within the application. As the Service Graph Connector for Wiz supports only a single instance, you can configure the default connection for the first time or resume editing it thereafter.
Complete the initial prerequisites when setting up a connection for the first time using a connector.
Note: This step is required when configuring the connector for the first time only. See Perform initial setup tasks when creating a connection in SGC Central.
Enter connection details and test the API connection for importing Wiz data.
In the Setup stage of the playbook, select the Create and test connection activity.
On the form, fill in the fields.
| Field | Description |
|---|---|
| Connection name | Name to identify the Wiz connection record. |
| Connection URL | Base URL to connect to your Wiz application. Note: Based on the region of your Wiz application, enter the connection URL in the following format: Where <region> is the region where the Wiz tenant is located. For example, us1, us2, eu1, or eu2. |
| Client ID | Client ID of your Wiz application as described in Before you begin. |
| Client secret | Client secret of your Wiz application as described in Before you begin. |
| OAuth token URL | Token generation URL. This field is automatically set to the following URL: |
3. Select **Update and test connection**.
4. Once the connection test is complete, select **Continue**.
Configure properties of the connector to access resources.
Note: To skip this step, select Continue for the Set configuration properties activity.
In the Setup stage of the playbook, select the Set configuration properties activity.
On the form, fill in the fields.
| Field | Description |
|---|---|
| Projects | List of project IDs for which the resources are to be imported.Separate multiple entries with a comma. |
| Exclude projects | List of project IDs for which the resources are excluded only when the Projects property isn’t set. In this case, all the resources except for the specified projects are imported.Separate multiple entries with a comma. |
3. Select **Continue**.
Configure the import schedule to import data at regular intervals.
In the Setup stage of the playbook, select the Configure import schedule activity.
Expand the Parent scheduled data import within the Import schedules list to select the SG-Wiz-Organization import schedule.
Select the Active check box, and then fill in the run schedule and time details.
For more information, see Schedule a data import.
Select Save.
Alternatively, select Execute Now to execute the import schedule immediately.
Enable the
Reset Last Run Datetime for SG-Wizscript to retrieve full data periodically.Note: To skip this step, select Skip for the Enable full data retrieval activity.
In the Setup stage of the playbook, select the Enable full data retrieval activity.
Select the Active check box, and then fill in the run schedule and time details.
Note: When active, the script clears the Last Run Date Time field value in a data source, ensuring that the SG-Wiz Organization scheduled job retrieves all Wiz-related data sources periodically.
Select Continue.
In the Setup stage of the playbook, select the Confirm connection creation activity to verify whether the connection was created.
What to do next
Select View all connections to review the connection details. The created connection appears in the Installed connections list.
Related topics
Service Graph Connector for Wiz
Target tables for storing Service Graph Connector for Wiz data
Service Graph Connector for Wiz properties
Accessing the connection details of Service Graph Connector for Wiz