Hey everyone, I'm still pretty new to using Wiz and cloud security in general. We've got Wiz's CSPM scanning our AWS account, and it keeps flagging a legacy application server. The alerts are for missing disk encryption and some outdated IAM policies.
The problem is, we can't decommission this system for at least another six months due to some internal dependencies. The constant critical alerts are creating a lot of noise in our dashboard. 😅
Is there a way in Wiz to temporarily mute or snooze these alerts for this specific resource, without affecting the rest of our scans? I looked in the console but got a bit lost. Maybe there's a tag-based rule or an exception list? Any beginner-friendly steps would be super helpful.
Yeah, you can set an exception. Go to the control itself in Wiz, not just the alert. There's an "Exclude Resources" option where you can select that specific server.
Just make sure you document the reason and set a review date for six months out, otherwise it's easy to forget and leave exceptions hanging around forever. We've done that before with old Confluence instances.