About The Device
Zscaler Internet Access (ZIA) is a secure internet and web gateway delivered as a service from the cloud. Think of ZIA as a secure internet onramp—just make Zscaler your next hop to the internet via one of the following methods:
Setting up a tunnel (GRE or IPSec) to the closest Zscaler data center (for offices).
Forwarding traffic via our lightweight Zscaler Client Connector or PAC file (for mobile employees).
Device Information
Entity | Particulars |
---|---|
Vendor Name | Zscaler |
Product Name | Internet Access |
Type of Device | Cloud |
Collection Method
Log Type | Ingestion label | Preferred Logging Protocol - Format | Log Collection MethodData Source |
---|---|---|---|
Zscaler Web | ZSCALER_WEBPROXY | Syslog - CEF JSON | C2C |
Zscaler Firewall | ZSCALER_FIREWALL | Syslog - CEF JSON | C2C |
Zscaler DNS | ZSCALER_DNS | Syslog - CEF JSON | C2C |
Device Configuration
To Configure Zscaler for NSS CLoud
Configure the Cloud NSS Feed on ZIA Admin Portal
Feed Name: Enter or edit the name of the feed. Each feed is a connection between the NSS and Chronicle.
NSS Type: NSS for Web.
Status: Enabled.
SIEM Rate: Unlimited.
SIEM Type: Other
OAuth 2.0 Authentication: Disabled
JSON Array Notation: Disabled.
Max Batch Size: 512 KB.
API URL: Endpoint URL provided by AMXDR Onboarding Team
HTTP Headers:
Key 1: X-Webhook-Access-Key
Value 1: API secret key generated on webhook. This will be provided by Adaptive MxDR Onboarding Team
Key 2: X-goog-api-key
Value 2: API Key generated on GCP BYOP’s API Credentials. This will be provided by Adaptive MxDR Onboarding Team
Log Type: Web Log.
Feed Output Type: JSON
Feed Escape Character: Keep the default value.
Feed Output Format: Keep the default value.
JSON Array Notation: Disabled
Timezone: Set UTC.
Ensure your settings are saved and test the connectivity. You should see a green checkmark with the message: "Test Connectivity Successful: OK (200)." Repeat the entire process for both Log Types: Firewall and DNS.
Integration Parameters:
Integration via Webhook:
Configure Webhook on Google Chronicle Instance.