...
Log Type | Ingestion label | Preferred Logging Protocol - Format | Log Collection MethodData SourceMethod |
---|---|---|---|
Zscaler Web | ZSCALER_WEBPROXYSyslog - CEF | JSON | C2C - Push |
Zscaler FirewallNGFW | ZSCALER_FIREWALL | Syslog - CEF JSON | C2C - Push |
Zscaler DNS | ZSCALER_DNS | JSON | Syslog - CEFC2C - Push |
Zscaler Internet Access Audit Logs | ZSCALER_INTERNET_ACCESS | JSON | C2C - Push |
Device Configuration
To Configure Zscaler for NSS CLoud
Configure the Cloud NSS Feed on ZIA Admin Portal
Feed Name: Enter or edit the name of the feed. Each feed is a connection between the NSS and Chronicle.
NSS Type:
NSS for Web
: Select this Type to ingest WebProxy Logs
NSS for Firewall : Select this Type to ingest Firewall Logs
Status: Enabled.
SIEM Rate: Unlimited.
SIEM Type: Other
OAuth 2.0 Authentication: Disabled
JSON Array Notation: Disabled.
Max Batch Size: 512 KB.
API URL: Endpoint URL provided by AMXDR Onboarding Team
HTTP Headers:
Key Header 1: X-Webhookgoog-Accessapi-Keykey
Value 1: API secret key Key generated on webhookGCP BYOP’s API Credentials. This will be provided by Adaptive MxDR AMXDR Onboarding Team
Key Header 2: X-googWebhook-apiAccess-keyKey
Value 2: API Key secret key generated on GCP BYOP’s API Credentialswebhook. This will be provided by Adaptive MxDR AMXDR Onboarding Team
Log Type:
Web Log: Select this to ingest Web Logs. This LogType is subtype of NSS For Web NSS Type as mentioned in option b. above
Admin Audit Logs: Select this to ingest Admin Audit Logs . This LogType is subtype of NSS For Web NSS Type as mentioned in option b. above
Firewall Logs: Select this to ingest Firewall Logs. This LogType is subtype of NSS For Firewall NSS Type as mentioned in option b. above
DNS Logs: Select this to ingest DNS Logs. This LogType is subtype of NSS For Firewall NSS Type as mentioned in option b. above
Feed Output Type: JSON
Feed Escape Character: Keep the default value. ,\"
Feed Output Format: Keep the default value.
JSON Array Notation: Disabled
Timezone: Set UTC.
Ensure Save your settings are saved and test the your connectivity. You should see a green checkmark check mark with the message : " Test Connectivity Successful: OK (200). " Repeat the entire process for both Log Types: Firewall and DNS.
...
Above mentioned configuration is similar for all log types : Web, Firewall, DNS and Admin Audit Logs.
Please find below table for NSS types and their respective Log types for easier configuration.
NSS Type | Log Type |
---|---|
NSS for Web |
|
NSS for Firewall |
|
Integration Parameters
Integration via Webhook:
Configure Webhook on Google Chronicle Instance.