Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

Version 1 Current »

About The Device

Zscaler Internet Access (ZIA) is a secure internet and web gateway delivered as a service from the cloud. Think of ZIA as a secure internet onramp—just make Zscaler your next hop to the internet via one of the following methods:

  • Setting up a tunnel (GRE or IPSec) to the closest Zscaler data center (for offices).

  • Forwarding traffic via our lightweight Zscaler Client Connector or PAC file (for mobile employees).

Device Information

 Entity

Particulars

Vendor Name

Zscaler

Product Name

Internet Access

Type of Device

Cloud

Collection Method

Log Type

 Ingestion label

Preferred Logging Protocol - Format

Log Collection MethodData Source

Zscaler Web

ZSCALER_WEBPROXY

Syslog - CEF

JSON

C2C

Zscaler Firewall

ZSCALER_FIREWALL

Syslog - CEF

JSON

C2C

Zscaler DNS

ZSCALER_DNS

Syslog - CEF

JSON

C2C

Device Configuration

To Configure Zscaler for NSS CLoud

  1. Configure the Cloud NSS Feed on ZIA Admin Portal

    1. Feed Name: Enter or edit the name of the feed. Each feed is a connection between the NSS and Chronicle.

    2. NSS Type: NSS for Web.

    3. Status: Enabled.

    4. SIEM Rate: Unlimited.

    5. SIEM Type: Other

    6. OAuth 2.0 Authentication: Disabled

    7. JSON Array Notation: Disabled.

    8. Max Batch Size: 512 KB.

    9. API URL: Endpoint URL provided by AMXDR Onboarding Team

    10. HTTP Headers:

      1. Key 1: X-Webhook-Access-Key

      2. Value 1: API secret key generated on webhook. This will be provided by Adaptive MxDR Onboarding Team

      3. Key 2: X-goog-api-key

      4. Value 2: API Key generated on GCP BYOP’s API Credentials. This will be provided by Adaptive MxDR Onboarding Team

    11. Log Type: Web Log.

    12. Feed Output Type: JSON

    13. Feed Escape Character: Keep the default value.

    14. Feed Output Format: Keep the default value.

    15. JSON Array Notation: Disabled

    16. Timezone: Set UTC.

image-20241202-113059.png

Ensure your settings are saved and test the connectivity. You should see a green checkmark with the message: "Test Connectivity Successful: OK (200)." Repeat the entire process for both Log Types: Firewall and DNS.

Integration Parameters:

Integration via Webhook:

Configure Webhook on Google Chronicle Instance.

  • No labels