Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Log Type

 Ingestion label

Preferred Logging Protocol - Format

Log Collection Method

Zscaler

ZSCALER_WEBPROXY

JSON

C2C - Push

Zscaler NGFW

ZSCALER_FIREWALL

JSON

C2C - Push

Zscaler DNS

ZSCALER_DNS

JSON

C2C - Push

Zscaler Internet Access Audit Logs

ZSCALER_INTERNET_ACCESS

JSON

C2C - Push

Zscaler Tunnel

ZSCALER_TUNNEL

JSON

C2C - Push

Zscaler DLP

ZSCALER_DLP

JSON

C2C - Push

Device Configuration

To Configure Zscaler for NSS CLoud

  1. Configure the Cloud NSS Feed on ZIA Admin Portal

    1. Feed Name: Enter or edit the name of the feed. Each feed is a connection between the NSS and Chronicle.

    2. NSS Type:

      1. NSS for Web: Select this Type to ingest WebProxy Logs

      2. NSS for Firewall: Select this Type to ingest Firewall Logs

      3. NSS for Tunnel : Select this Type to ingest Tunnel Logs

    3. Status: Enabled.

    4. SIEM Rate: Unlimited.

    5. SIEM Type: Other

    6. OAuth 2.0 Authentication: Disabled

    7. JSON Array Notation: Disabled.

    8. Max Batch Size: 512 KB.

    9. API URL: Endpoint URL provided by AMXDR Onboarding Team

    10. HTTP Headers:

      1. Header 1: X-goog-api-key

      2. Value 1: API Key generated on GCP BYOP’s API Credentials. This will be provided by AMXDR Onboarding Team

      3. Header 2: X-Webhook-Access-Key

      4. Value 2: API secret key generated on webhook. This will be provided by AMXDR Onboarding Team

    11. Log Type:

      1. Web Log: Select this to ingest Web Logs. This LogType is subtype of NSS For Web NSS Type as mentioned in option b. above

      2. Admin Audit Logs: Select this to ingest Admin Audit Logs. This LogType is subtype of NSS For Web NSS Type as mentioned in option b. above

      3. Endpoint DLP: Select this to ingest Endpoint DLP Logs. This LogType is subtype of NSS For Web NSS Type as mentioned in option b. above

      4. Firewall Logs : Select this to ingest Firewall Logs. This LogType is subtype of NSS For Firewall NSS Type as mentioned in option b. above

      5. DNS Logs: Select this to ingest DNS Logs. This LogType is subtype of NSS For Firewall NSS Type as mentioned in option b. above

      6. Tunnel Logs: Select this to ingest Tunnel Logs. This LogType is subtype of NSS For Tunnel NSS Type as mentioned in option b. above

    12. Feed Output Type: JSON

    13. Feed Escape Character: ,\"

    14. Feed Output Format: Keep the default value.

    15. JSON Array Notation: Disabled

    16. Timezone: Set UTC.

...

NSS Type

Log Type

NSS for Web

  1. Web Log

  2. Admin Audit Logs

NSS for Firewall

  1. Firewall Logs

  2. DNS Logs

NSS for Tunnel

  1. Tunnel Logs

Integration Parameters

Integration via Webhook:

...