...
Log Type | Ingestion label | Preferred Logging Protocol - Format | Log Collection Method |
---|---|---|---|
Zscaler | ZSCALER_WEBPROXY | JSON | C2C - Push |
Zscaler NGFW | ZSCALER_FIREWALL | JSON | C2C - Push |
Zscaler DNS | ZSCALER_DNS | JSON | C2C - Push |
Zscaler Internet Access Audit Logs | ZSCALER_INTERNET_ACCESS | JSON | C2C - Push |
Zscaler Tunnel | ZSCALER_TUNNEL | JSON | C2C - Push |
Zscaler DLP | ZSCALER_DLP | JSON | C2C - Push |
Device Configuration
To Configure Zscaler for NSS CLoud
Configure the Cloud NSS Feed on ZIA Admin Portal
Feed Name: Enter or edit the name of the feed. Each feed is a connection between the NSS and Chronicle.
NSS Type:
NSS for Web: Select this Type to ingest WebProxy Logs
NSS for Firewall: Select this Type to ingest Firewall Logs
NSS for Tunnel : Select this Type to ingest Tunnel Logs
Status: Enabled.
SIEM Rate: Unlimited.
SIEM Type: Other
OAuth 2.0 Authentication: Disabled
JSON Array Notation: Disabled.
Max Batch Size: 512 KB.
API URL: Endpoint URL provided by AMXDR Onboarding Team
HTTP Headers:
Header 1: X-goog-api-key
Value 1: API Key generated on GCP BYOP’s API Credentials. This will be provided by AMXDR Onboarding Team
Header 2: X-Webhook-Access-Key
Value 2: API secret key generated on webhook. This will be provided by AMXDR Onboarding Team
Log Type:
Web Log: Select this to ingest Web Logs. This LogType is subtype of NSS For Web NSS Type as mentioned in option b. above
Admin Audit Logs: Select this to ingest Admin Audit Logs. This LogType is subtype of NSS For Web NSS Type as mentioned in option b. above
Endpoint DLP: Select this to ingest Endpoint DLP Logs. This LogType is subtype of NSS For Web NSS Type as mentioned in option b. above
Firewall Logs : Select this to ingest Firewall Logs. This LogType is subtype of NSS For Firewall NSS Type as mentioned in option b. above
DNS Logs: Select this to ingest DNS Logs. This LogType is subtype of NSS For Firewall NSS Type as mentioned in option b. above
Tunnel Logs: Select this to ingest Tunnel Logs. This LogType is subtype of NSS For Tunnel NSS Type as mentioned in option b. above
Feed Output Type: JSON
Feed Escape Character: ,\"
Feed Output Format: Keep the default value.
JSON Array Notation: Disabled
Timezone: Set UTC.
...
NSS Type | Log Type |
---|---|
NSS for Web |
|
NSS for Firewall |
|
NSS for Tunnel |
|
Integration Parameters
Integration via Webhook:
...