Skip to end of metadata
Go to start of metadata

You are viewing an old version of this content. View the current version.

Compare with Current View Version History

« Previous Version 4 Next »

About The Device

Zscaler Internet Access (ZIA) is a secure internet and web gateway delivered as a service from the cloud. Think of ZIA as a secure internet onramp—just make Zscaler your next hop to the internet via one of the following methods:

  • Setting up a tunnel (GRE or IPSec) to the closest Zscaler data center (for offices).

  • Forwarding traffic via our lightweight Zscaler Client Connector or PAC file (for mobile employees).

Device Information

 Entity

Particulars

Vendor Name

Zscaler

Product Name

Internet Access

Type of Device

Cloud

Collection Method

Log Type

 Ingestion label

Preferred Logging Protocol - Format

Log Collection Method

Zscaler

ZSCALER_WEBPROXY

JSON

C2C - Push

Zscaler NGFW

ZSCALER_FIREWALL

JSON

C2C - Push

Zscaler DNS

ZSCALER_DNS

JSON

C2C - Push

Zscaler Internet Access Audit Logs

ZSCALER_INTERNET_ACCESS

JSON

C2C - Push

Device Configuration

To Configure Zscaler for NSS CLoud

  1. Configure the Cloud NSS Feed on ZIA Admin Portal

    1. Feed Name: Enter or edit the name of the feed. Each feed is a connection between the NSS and Chronicle.

    2. NSS Type:

      1. NSS for Web: Select this Type to ingest WebProxy Logs

      2. NSS for Firewall : Select this Type to ingest Firewall Logs

    3. Status: Enabled.

    4. SIEM Rate: Unlimited.

    5. SIEM Type: Other

    6. OAuth 2.0 Authentication: Disabled

    7. JSON Array Notation: Disabled.

    8. Max Batch Size: 512 KB.

    9. API URL: Endpoint URL provided by AMXDR Onboarding Team

    10. HTTP Headers:

      1. Header 1: X-goog-api-key

      2. Value 1: API Key generated on GCP BYOP’s API Credentials. This will be provided by AMXDR Onboarding Team

      3. Header 2: X-Webhook-Access-Key

      4. Value 2: API secret key generated on webhook. This will be provided by AMXDR Onboarding Team

    11. Log Type:

      1. Web Log: Select this to ingest Web Logs. This LogType is subtype of NSS For Web NSS Type as mentioned in option b. above

      2. Admin Audit Logs: Select this to ingest Admin Audit Logs . This LogType is subtype of NSS For Web NSS Type as mentioned in option b. above

      3. Firewall Logs: Select this to ingest Firewall Logs. This LogType is subtype of NSS For Firewall NSS Type as mentioned in option b. above

      4. DNS Logs: Select this to ingest DNS Logs. This LogType is subtype of NSS For Firewall NSS Type as mentioned in option b. above

    12. Feed Output Type: JSON

    13. Feed Escape Character: ,\"

    14. Feed Output Format: Keep the default value.

    15. JSON Array Notation: Disabled

    16. Timezone: Set UTC.

image-20241202-113059.png

Save your settings and test your connectivity. You should see a green check mark with the message Test Connectivity Successful: OK (200). Above mentioned configuration is similar for all log types : Web, Firewall, DNS and Admin Audit Logs.

Please find below table for NSS types and their respective Log types for easier configuration.

NSS Type

Log Type

NSS for Web

  1. Web Log

  2. Admin Audit Logs

NSS for Firewall

  1. Firewall Logs

  2. DNS Logs

Integration Parameters

Integration via Webhook:

Configure Webhook on Google Chronicle Instance.

  • No labels