About The Device
Zscaler Internet Access (ZIA) is a secure internet and web gateway delivered as a service from the cloud. Think of ZIA as a secure internet onramp—just make Zscaler your next hop to the internet via one of the following methods:
Setting up a tunnel (GRE or IPSec) to the closest Zscaler data center (for offices).
Forwarding traffic via our lightweight Zscaler Client Connector or PAC file (for mobile employees).
Device Information
Entity | Particulars |
---|---|
Vendor Name | Zscaler |
Product Name | Internet Access |
Type of Device | Cloud |
Collection Method
Log Type | Ingestion label | Preferred Logging Protocol - Format | Log Collection Method |
---|---|---|---|
Zscaler | ZSCALER_WEBPROXY | JSON | C2C - Push |
Zscaler NGFW | ZSCALER_FIREWALL | JSON | C2C - Push |
Zscaler DNS | ZSCALER_DNS | JSON | C2C - Push |
Zscaler Internet Access Audit Logs | ZSCALER_INTERNET_ACCESS | JSON | C2C - Push |
Device Configuration
To Configure Zscaler for NSS CLoud
Configure the Cloud NSS Feed on ZIA Admin Portal
Feed Name: Enter or edit the name of the feed. Each feed is a connection between the NSS and Chronicle.
NSS Type:
NSS for Web: Select this Type to ingest WebProxy Logs
NSS for Firewall : Select this Type to ingest Firewall Logs
Status: Enabled.
SIEM Rate: Unlimited.
SIEM Type: Other
OAuth 2.0 Authentication: Disabled
JSON Array Notation: Disabled.
Max Batch Size: 512 KB.
API URL: Endpoint URL provided by AMXDR Onboarding Team
HTTP Headers:
Header 1: X-goog-api-key
Value 1: API Key generated on GCP BYOP’s API Credentials. This will be provided by AMXDR Onboarding Team
Header 2: X-Webhook-Access-Key
Value 2: API secret key generated on webhook. This will be provided by AMXDR Onboarding Team
Log Type:
Web Log: Select this to ingest Web Logs. This LogType is subtype of NSS For Web NSS Type as mentioned in option b. above
Admin Audit Logs: Select this to ingest Admin Audit Logs . This LogType is subtype of NSS For Web NSS Type as mentioned in option b. above
Firewall Logs: Select this to ingest Firewall Logs. This LogType is subtype of NSS For Firewall NSS Type as mentioned in option b. above
DNS Logs: Select this to ingest DNS Logs. This LogType is subtype of NSS For Firewall NSS Type as mentioned in option b. above
Feed Output Type: JSON
Feed Escape Character: ,\"
Feed Output Format: Keep the default value.
JSON Array Notation: Disabled
Timezone: Set UTC.
Save your settings and test your connectivity. You should see a green check mark with the message Test Connectivity Successful: OK (200). Above mentioned configuration is similar for all log types : Web, Firewall, DNS and Admin Audit Logs.
Please find below table for NSS types and their respective Log types for easier configuration.
NSS Type | Log Type |
---|---|
NSS for Web |
|
NSS for Firewall |
|
Integration Parameters
Integration via Webhook:
Configure Webhook on Google Chronicle Instance.