RunReveal
SourcesSource TypesWiz

Wiz Runtime Sensor Events

Collect Wiz Runtime Sensor Events from remote object storage.

Wiz Runtime Sensor Events source tile

Ingest Methods

RunReveal offers the following ways to ingest Wiz Runtime Sensor Events logs:

If using an AWS S3 bucket use the following SNS topic ARN to send your bucket notifications.

arn:aws:sns:<REGION>:253602268883:runreveal_wiz_runtime

Replace <REGION> with the AWS region where your S3 bucket is located (e.g., us-east-1, us-west-2, eu-west-1).

SNS topic & Custom SQS. Use the ARN above in your event notification tied to your S3 bucket—the topic name must match (runreveal_…; hyphens in the source id become underscores). For Custom SQS, set the queue URL and region in RunReveal; see AWS S3 Bucket with Custom SQS.

Note: BYOC, On-Prem, and BYODB customers must use their AWS account ID in the ARN instead of 253602268883.

Schema

The following columns are exposed for this source. RunReveal applies schema normalization across all sources, ensuring uniform field names and data types for cross-source queries and reusable detection logic.

Table: wiz_runtime_logs (137 columns)

ColumnType
workspaceIDString
sourceIDString
sourceTypeString
sourceTTLUInt32
receivedAtDateTime
idString
eventTimeDateTime
eventNameString
eventIDString
srcIPString
srcASCountryCodeString
srcASNumberUInt32
srcASOrganizationString
srcCityString
srcConnectionTypeString
srcISPString
srcLatitudeFloat64
srcLongitudeFloat64
srcUserTypeString
dstIPString
dstASCountryCodeString
dstASNumberUInt32
dstASOrganizationString
dstCityString
dstConnectionTypeString
dstISPString
dstLatitudeFloat64
dstLongitudeFloat64
dstUserTypeString
actorMap(String, String)
tagsMap(String, String)
resourcesArray(String)
serviceNameString
enrichmentsArray(Tuple(data Map(String, String), name String, provider String, type String, value String))
readOnlyBool
rawLogString
originString
kindString
severityString
uniqueTimeString
wizIngestionStartTimeString
tenantIdString
dataOriginIdString
dataOriginProviderInt32
cloudPlatformString
rawEventNameString
wizEventNameString
eventSourceString
commandLineString
resultInt32
verboseEventBool
targetTableInt32
internalEventSourceString
hashArray(String)
imageNamesArray(String)
imageInternalIdsArray(String)
imageExternalIdsArray(String)
imageDigestsArray(String)
imageReferencesArray(String)
resourcesExternalIdsArray(String)
resourcesInternalIdsArray(String)
resourcesContainerNamesArray(String)
resourcesContainerExternalIdsArray(String)
subjectResourceExternalIdString
subjectResourceInternalIdString
subjectResourceTypeString
subjectResourceNativeTypeString
subjectResourceNameString
subjectResourceSubscriptionIdString
ColumnType
subjectResourceRegionString
actorSessionCreationDateString
runtimeProgramIdString
runtimeProgramNameString
runtimeProgramUserIdString
runtimeProgramUserIdNumberInt32
runtimeProgramScriptNameString
runtimeProgramScriptPathString
runtimeProgramScriptSha1String
runtimeProgramIsDriftedBool
runtimeProgramRunningProgramIdString
parentRuntimeProgramIdString
parentRuntimeProgramNameString
parentRuntimeProgramUserIdString
parentRuntimeProgramScriptNameString
parentRuntimeProgramScriptPathString
parentRuntimeProgramScriptSha1String
sensorIdString
sensorExternalIdString
sensorAlertIdString
sensorAlertTypeString
sensorContainerExternalIdString
sensorDnsQueryString
sensorContainerRegistryString
sensorContainerImageNameString
sensorImageHashString
sensorImageTagString
sensorImageReferenceString
sensorSensorTypeString
sensorHostNameString
sensorHostExternalIdString
sensorVmImageString
sensorDetectedIpString
sensorDetectedIncomingIpString
sensorDetectedDomainString
sensorLocalUsernameString
executionScopeIdString
executionScopeExternalIdString
executionScopeTypeString
executionScopeUserNameString
eventSubscriptionIdString
eventSubscriptionTypeString
eventSubscriptionInternalIdString
eventSubscriptionCloudPlatformString
decorationsActorHasAdminPrivilegesBool
decorationsActorHasHighPrivilegesBool
decorationsActorHasAdminKubernetesPrivilegesBool
decorationsActorHasHighKubernetesPrivilegesBool
decorationsActorIpIsForeignBool
decorationsActorInactiveInLast90DaysBool
decorationsSubjectResourceIsOpenToAllInternetBool
decorationsSubjectResourceHasSensitiveDataBool
decorationsActorIpReputationInt32
decorationsActorIpReputationSourceString
decorationsActorIpReputationDescriptionString
decorationsNetworkConnectionSourceIpReputationInt32
decorationsNetworkConnectionSourceIpReputationSourceString
decorationsNetworkConnectionSourceIpReputationDescriptionString
decorationsNetworkConnectionSourceIpIsForeignBool
decorationsNetworkConnectionSourceIpIsInternalBool
decorationsNetworkConnectionDestinationIpReputationInt32
decorationsNetworkConnectionDestinationIpReputationSourceString
decorationsNetworkConnectionDestinationIpReputationDescriptionString
decorationsNetworkConnectionDestinationIpIsForeignBool
decorationsNetworkConnectionDestinationIpIsInternalBool
decorationsDnsQueryDomainReputationInt32
decorationsDnsQueryDomainReputationSourceString
decorationsDnsQueryDomainReputationDescriptionString

On this page