Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Log Type

 Ingestion label

Preferred Logging Protocol - Format

Log Collection MethodData SourceMethod

Zscaler Web

ZSCALER_WEBPROXYSyslog - CEF

JSON

C2C - Push

Zscaler FirewallNGFW

ZSCALER_FIREWALL

Syslog - CEF

JSON

C2C - Push

Zscaler DNS

ZSCALER_DNS

JSON

Syslog - CEFC2C - Push

Zscaler Internet Access Audit Logs

ZSCALER_INTERNET_ACCESS

JSON

C2C - Push

Device Configuration

To Configure Zscaler for NSS CLoud

  1. Configure the Cloud NSS Feed on ZIA Admin Portal

    1. Feed Name: Enter or edit the name of the feed. Each feed is a connection between the NSS and Chronicle.

    2. NSS Type:

      1. NSS for Web

      .
      1. : Select this Type to ingest WebProxy Logs

      2. NSS for Firewall : Select this Type to ingest Firewall Logs

    3. Status: Enabled.

    4. SIEM Rate: Unlimited.

    5. SIEM Type: Other

    6. OAuth 2.0 Authentication: Disabled

    7. JSON Array Notation: Disabled.

    8. Max Batch Size: 512 KB.

    9. API URL: Endpoint URL provided by AMXDR Onboarding Team

    10. HTTP Headers:

      1. Key Header 1: X-Webhookgoog-Accessapi-Keykey

      2. Value 1: API secret key Key generated on webhookGCP BYOP’s API Credentials. This will be provided by Adaptive MxDR AMXDR Onboarding Team

      3. Key Header 2: X-googWebhook-apiAccess-keyKey

      4. Value 2: API Key secret key generated on GCP BYOP’s API Credentialswebhook. This will be provided by Adaptive MxDR AMXDR Onboarding Team

    11. Log Type:

      1. Web Log: Select this to ingest Web Logs. This LogType is subtype of NSS For Web NSS Type as mentioned in option b. above

      2. Admin Audit Logs: Select this to ingest Admin Audit Logs . This LogType is subtype of NSS For Web NSS Type as mentioned in option b. above

      3. Firewall Logs: Select this to ingest Firewall Logs. This LogType is subtype of NSS For Firewall NSS Type as mentioned in option b. above

      4. DNS Logs: Select this to ingest DNS Logs. This LogType is subtype of NSS For Firewall NSS Type as mentioned in option b. above

    12. Feed Output Type: JSON

    13. Feed Escape Character: Keep the default value. ,\"

    14. Feed Output Format: Keep the default value.

    15. JSON Array Notation: Disabled

    16. Timezone: Set UTC.

image-20241202-113059.png

Ensure Save your settings are saved and test the your connectivity. You should see a green checkmark check mark with the message : " Test Connectivity Successful: OK (200). " Repeat the entire process for both Log Types: Firewall and DNS.

...

Above mentioned configuration is similar for all log types : Web, Firewall, DNS and Admin Audit Logs.

Please find below table for NSS types and their respective Log types for easier configuration.

NSS Type

Log Type

NSS for Web

  1. Web Log

  2. Admin Audit Logs

NSS for Firewall

  1. Firewall Logs

  2. DNS Logs

Integration Parameters

Integration via Webhook:

Configure Webhook on Google Chronicle Instance.