# Z Scaler Integrations

##### <span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans" data-ccp-charstyle-defn="{"ObjectId":"9697cb23-59f2-4ed7-b428-0aa745846b1c|145","ClassId":1073872969,"Properties":[469775450,"Style (Complex) Open Sans",201340122,"1",134233614,"true",469778129,"StyleComplexOpenSans",335572020,"1",201342448,"1",469777841,"Open Sans",469777842,"Open Sans",469777843,"Calibri",469777844,"Open Sans",469769226,"Open Sans,Calibri",469778324,"Default Paragraph Font"]}">Introduction</span></span>**<span class="EOP SCXW42879288 BCX8" data-ccp-props="{"134245418":true,"134245529":true,"201341983":0,"335559738":240,"335559739":0,"335559740":360}"> </span></span>

<span class="TextRun SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">This integration is for </span><span class="NormalTextRun SCXW42879288 BCX8">Zscaler</span><span class="NormalTextRun SCXW42879288 BCX8"> Internet Access logs. It can be used to receive logs sent by NSS log server on respective TCP ports.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559685":360,"335559739":160,"335559740":259}"> </span>

<span class="TextRun SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">The log message is expected to be in JSON format. The data is mapped to ECS fields where </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW42879288 BCX8">applicable</span><span class="NormalTextRun SCXW42879288 BCX8"> and the remaining fields are written under </span></span><span class="TextRun SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SpellingErrorV2Themed SCXW42879288 BCX8">zscaler\_</span><span class="NormalTextRun SpellingErrorV2Themed SCXW42879288 BCX8">zia</span><span class="NormalTextRun SCXW42879288 BCX8">.&lt;</span><span class="NormalTextRun SCXW42879288 BCX8">data-stream-name&gt;.\*</span></span><span class="TextRun SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559685":360,"335559739":160,"335559740":259}"> </span>

<span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559685":360,"335559739":160,"335559740":259}"> </span>

##### <span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">Assumptions</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"134245418":true,"134245529":true,"201341983":0,"335559738":240,"335559739":0,"335559740":360}"> </span>**</span>

<span class="TextRun SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">The procedures described in Section </span></span><span class="FieldRange SCXW42879288 BCX8"><span class="TextRun SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">3</span></span></span><span class="TextRun SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"> <span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">assumes</span><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans"> that a Log Collector has already been </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">setup</span><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">. </span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559685":360,"335559739":160,"335559740":259}"> </span>

**<span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">Compatibility</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"134245418":true,"134245529":true,"201341983":0,"335559738":240,"335559739":0,"335559740":360}"> </span>**

<span class="TextRun SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">This package has been tested against </span></span><span class="TextRun SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Zscaler Internet Access version </span><span class="NormalTextRun SCXW42879288 BCX8">6.1</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559685":1440,"335559739":160,"335559740":259}"> </span>

<span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559685":720,"335559731":720,"335559739":160,"335559740":259}"> </span>

##### <span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">Requirements</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"134245418":true,"134245529":true,"201341983":0,"335559738":240,"335559739":0,"335559740":360}"> </span>**</span>

**<span class="TextRun SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">Steps for setting up NSS Feeds</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span>**

<div class="SCXW42879288 BCX8" id="bkmrk-enable-the-integrati"><div class="ListContainerWrapper SCXW42879288 BCX8">1. <span class="TextRun SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">Enable the integration with the TCP input.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span>

</div><div class="ListContainerWrapper SCXW42879288 BCX8">2. <span class="TextRun SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">Configure the Zscaler NSS Server and NSS Feeds to send logs to the Elastic Agent that is running this integration. See Add NSS Server and Add NSS Feeds. Use the IP address hostname of the Elastic Agent as the 'NSS Feed SIEM IP Address/FQDN</span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">', and</span><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans"> use the listening port of the Elastic Agent as the 'SIEM TCP Port' on the Add NSS Feed configuration screen. To configure Zscaler NSS Server and NSS Feeds follow the following steps.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span>

</div><div class="ListContainerWrapper SCXW42879288 BCX8">- <span class="TextRun SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">In the ZIA Admin Portal, add an NSS Server.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span>

</div><div class="ListContainerWrapper SCXW42879288 BCX8">- <span class="TextRun SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">Log in to the ZIA Admin Portal using your admin account. If </span><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">you're</span><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans"> unable to log in, contact Support.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span>
- <span class="TextRun SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">Add an NSS server. Refer to Adding NSS Servers to set up an Add NSS Server for Web and/or Firewall.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span>
- <span class="TextRun SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">Verify that the state of the NSS Server is healthy.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span>
- <span class="TextRun SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">In the ZIA Admin Portal, go to Administration &gt; </span><span class="NormalTextRun SpellingErrorV2Themed SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">Nanolog</span><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans"> Streaming Service &gt; NSS Servers.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span>
- <span class="TextRun SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="Style (Complex) Open Sans">In the State column, confirm that the state of the NSS server is healthy.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span>

</div><div class="OutlineElement Ltr SCXW42879288 BCX8">  
</div></div><span class="SCXW42879288 BCX8"><span class="WACImageContainer NoPadding DragDrop BlobObject SCXW42879288 BCX8" role="presentation">![Graphical user interface, text

Description automatically generated](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2024-04/embedded-image-7appumqi.png)</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559685":720,"335559739":0,"335559740":240}"> </span>

<span class="SCXW42879288 BCX8"><span class="WACImageContainer NoPadding DragDrop BlobObject SCXW42879288 BCX8" role="presentation">![Shape NSS server setup image](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2024-04/embedded-image-2cx6wk9w.png)</span></span>

<div class="SCXW42879288 BCX8" id="bkmrk-in-the-zia-admin-por"><div class="ListContainerWrapper SCXW42879288 BCX8">- <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">In the ZIA Admin Portal, add an NSS Feed.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}"> </span>
- <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Refer to </span></span>[<span class="TextRun Underlined SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Add NSS Feeds</span></span>](https://help.zscaler.com/zia/adding-nss-feeds)<span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8"> and select the type of feed you want to configure. The following fields </span><span class="NormalTextRun SCXW42879288 BCX8">require</span><span class="NormalTextRun SCXW42879288 BCX8"> specific inputs:</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}"> </span>
- **<span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">SIEM IP Address</span></span>**<span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">: Enter the IP address of the </span></span>[<span class="TextRun Underlined SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Elastic agent</span></span>](https://www.elastic.co/guide/en/fleet/current/fleet-overview.html)<span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8"> </span><span class="NormalTextRun SCXW42879288 BCX8">you’ll</span><span class="NormalTextRun SCXW42879288 BCX8"> be assigning the Zscaler integration to.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}"> </span>
- **<span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">SIEM TCP Port</span></span>**<span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">: Enter the port number, depending on the logs associated with the NSS Feed. You will need to create an NSS Feed for each log type.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}"> </span>
    
    
    - <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Alerts</span></span><span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">: 9010</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}"> </span>
    - <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">DNS</span></span><span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">: 9011</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}"> </span>
    - <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Firewall</span></span><span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">: 9012</span></span>
    - <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Tunnel</span></span><span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">: 9013</span></span>
    - <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Web</span></span><span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">: 9014</span></span>

- **<span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Feed Output Type</span></span>**<span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">**:** Select Custom in Feed output type and paste the </span><span class="NormalTextRun SCXW42879288 BCX8">appropriate response</span><span class="NormalTextRun SCXW42879288 BCX8"> format in Feed output format as follows:</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}"> </span>

</div></div><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559685":3600,"335559739":0,"335559740":240}"> </span>

<span class="SCXW42879288 BCX8"><span class="WACImageContainer NoPadding DragDrop BlobObject SCXW42879288 BCX8" role="presentation">![Graphical user interface, application

Description automatically generated](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2024-04/embedded-image-vvtdgnrz.png)</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559685":2880,"335559739":0,"335559740":240}"> </span>

<span class="SCXW42879288 BCX8"><span class="WACImageContainer NoPadding DragDrop BlobObject SCXW42879288 BCX8" role="presentation">![Shape NSS Feeds setup image](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2024-04/embedded-image-pduvcrwm.png)</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559685":2160,"335559739":0,"335559740":240}"> </span>

<span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Steps for setting up Cloud NSS Feeds</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}"> </span>**</span>

<div class="SCXW42879288 BCX8" id="bkmrk-enable-the-integrati-1"><div class="ListContainerWrapper SCXW42879288 BCX8">1. <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Enable the integration with the HTTP Endpoint input.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}"> </span>

</div><div class="ListContainerWrapper SCXW42879288 BCX8">2. <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Configure the Zscaler Cloud NSS Feeds to send logs to the Elastic Agent that is running this integration. Provide API URL to send logs to the Elastic Agent. To configure Zscaler Cloud NSS Feeds follow the following steps.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}"> </span>

</div><div class="ListContainerWrapper SCXW42879288 BCX8">- <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">In the ZIA Admin Portal, add a Cloud NSS Feed.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}"> </span>
- <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Log in to the ZIA Admin Portal using your admin account.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}"> </span>
- <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Add a Cloud NSS Feed. See to </span></span>[<span class="TextRun Underlined SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Add Cloud NSS Feed</span></span>](https://help.zscaler.com/zia/adding-cloud-nss-feeds)<span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}"> </span>
- <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">In the ZIA Admin Portal, go to Administration &gt; </span><span class="NormalTextRun SpellingErrorV2Themed SCXW42879288 BCX8">Nanolog</span><span class="NormalTextRun SCXW42879288 BCX8"> Streaming Service &gt; Cloud NSS Feeds.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}"> </span>
- <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Give Feed Name, change status to Enabled.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}"> </span>
- <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Select NSS Type.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}"> </span>
- <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Change SIEM Type to </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW42879288 BCX8">other</span><span class="NormalTextRun SCXW42879288 BCX8">.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}"> </span>
- <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Add an API URL.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}"> </span>
- <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Default ports:</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}"> </span>
    
    
    - <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">DNS</span></span><span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">: 9556</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}"> </span>
    - <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Firewall</span></span><span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">: 9557</span></span>
    - <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Tunnel</span></span><span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">: 9558</span></span>
    - <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Web</span></span><span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">: 9559</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}"> </span>

</div></div><div class="SCXW42879288 BCX8" id="bkmrk-select-json-as-feed-"><div class="ListContainerWrapper SCXW42879288 BCX8">- <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Select JSON as feed output type.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}"> </span>
- <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Add </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW42879288 BCX8">same</span><span class="NormalTextRun SCXW42879288 BCX8"> custom header along with its value on </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW42879288 BCX8">both the side</span><span class="NormalTextRun SCXW42879288 BCX8"> for </span><span class="NormalTextRun SCXW42879288 BCX8">additional</span><span class="NormalTextRun SCXW42879288 BCX8"> security.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}"> </span>

</div><div class="OutlineElement Ltr SCXW42879288 BCX8">  
</div></div><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559685":1440,"335559739":0,"335559740":240}"> </span>

<span class="SCXW42879288 BCX8"><span class="WACImageContainer NoPadding DragDrop BlobObject SCXW42879288 BCX8" role="presentation">![Graphical user interface, text, application, email

Description automatically generated](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2024-04/embedded-image-q5y9sfv3.png)</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559685":1440,"335559739":0,"335559740":240}"> </span>

<div class="SCXW42879288 BCX8" id="bkmrk-repeat-step-2-for-ea"><div class="ListContainerWrapper SCXW42879288 BCX8">3. <span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Repeat step 2 for each log type.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}"> </span>

</div></div>**<span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Please make sure to use the given response formats for NSS and Cloud NSS Feeds.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559685":360,"335559739":0,"335559740":240}"> </span>**

<span class="TextRun SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Note: Please make sure to use </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW42879288 BCX8">latest</span><span class="NormalTextRun SCXW42879288 BCX8"> version of </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW42879288 BCX8">given</span><span class="NormalTextRun SCXW42879288 BCX8"> response formats.</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335557856":16777215,"335559685":360,"335559739":0,"335559740":240}"> </span>

<span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559685":360,"335559739":160,"335559740":259}"> </span>

<span class="EOP SCXW42879288 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335557856":16777215,"335559685":360,"335559738":0,"335559739":0,"335559740":240}"> </span>

##### <span style="color: rgb(53, 152, 219);">**<span class="TextRun Highlight SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="normaltextrun" data-ccp-charstyle-defn="{"ObjectId":"9697cb23-59f2-4ed7-b428-0aa745846b1c|171","ClassId":1073872969,"Properties":[469775450,"normaltextrun",201340122,"1",134233614,"true",469778129,"normaltextrun",335572020,"1",469778324,"Default Paragraph Font"]}">Zscaler</span> <span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="normaltextrun">I</span><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="normaltextrun">ntegration</span><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="eop" data-ccp-charstyle-defn="{"ObjectId":"9697cb23-59f2-4ed7-b428-0aa745846b1c|172","ClassId":1073872969,"Properties":[469775450,"eop",201340122,"1",134233614,"true",469778129,"eop",335572020,"1",469778324,"Default Paragraph Font"]}"> </span><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-charstyle="eop">Procedures</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"134245418":true,"134245529":true,"201341983":0,"335559738":240,"335559739":0,"335559740":360}"> </span>**</span>

<span class="TextRun Highlight SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Please provide the following information to </span><span class="NormalTextRun SpellingErrorV2Themed SCXW42879288 BCX8">CyTech</span><span class="NormalTextRun SCXW42879288 BCX8">:</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559685":360,"335559739":160,"335559740":259}"> </span>

<div class="SCXW42879288 BCX8" id="bkmrk--1"><div class="OutlineElement Ltr SCXW42879288 BCX8">  
</div><div class="ListContainerWrapper SCXW42879288 BCX8">  
</div></div>**<span class="TextRun Highlight SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-parastyle="CyTech Heading 1" data-ccp-parastyle-defn="{"ObjectId":"9697cb23-59f2-4ed7-b428-0aa745846b1c|115","ClassId":1073872969,"Properties":[469775450,"CyTech Heading 1",201340122,"2",134234082,"true",134233614,"true",469778129,"CyTechHeading1",335572020,"1",201342448,"2",469777841,"Open Sans",469777842,"Open Sans",469777843,"",469777844,"Open Sans",469769226,"Open Sans",335551500,"1809913",268442635,"36",335559740,"360",201341983,"0",335559739,"0",335559738,"240",335560102,"0",134245418,"true",134245529,"true",469777929,"CyTech Heading 1 Char",469778324,"heading 1"]}" data-ccp-parastyle-linked-defn="{"ObjectId":"9697cb23-59f2-4ed7-b428-0aa745846b1c|118","ClassId":1073872969,"Properties":[469775450,"CyTech Heading 1 Char",201340122,"1",134233614,"true",469778129,"CyTechHeading1Char",335572020,"1",134231262,"true",201342448,"2",469777841,"Open Sans",469777842,"Open Sans",469777843,"",469777844,"Open Sans",469769226,"Open Sans",335551500,"1809913",268442635,"36",335551547,"1033",469777929,"CyTech Heading 1",469778324,"Heading 1 Char"]}">Collect Zscaler Internet Access logs via TCP </span><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-parastyle="CyTech Heading 1">input</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"134245418":true,"134245529":true,"201341983":0,"335559738":240,"335559739":0,"335559740":360}"> </span>**

<div class="SCXW42879288 BCX8" id="bkmrk-listen-address---the"><div class="ListContainerWrapper SCXW42879288 BCX8">  
</div><div class="ListContainerWrapper SCXW42879288 BCX8" style="padding-left: 40px;">1. 1. <span class="TextRun Highlight SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Listen Address</span><span class="NormalTextRun SCXW42879288 BCX8"> - </span><span class="NormalTextRun SCXW42879288 BCX8">The bind address to listen for TCP connections.</span></span>
    2. <span class="TextRun Highlight SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Types: </span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span>

</div><div class="ListContainerWrapper SCXW42879288 BCX8">- - - - - - <span class="TextRun Highlight SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">TCP </span><span class="NormalTextRun SCXW42879288 BCX8">Listen Port for </span><span class="NormalTextRun SCXW42879288 BCX8">Zscaler</span><span class="NormalTextRun SCXW42879288 BCX8"> Internet Access Alerts</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span>

</div></div><div class="SCXW42879288 BCX8" id="bkmrk-tcp-listen-port-for-" style="padding-left: 40px;"><div class="ListContainerWrapper SCXW42879288 BCX8" style="padding-left: 40px;">- - <span class="TextRun Highlight SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">TCP </span><span class="NormalTextRun SCXW42879288 BCX8">Listen Port for </span><span class="NormalTextRun SCXW42879288 BCX8">Zscaler</span><span class="NormalTextRun SCXW42879288 BCX8"> Internet Access DNS </span><span class="NormalTextRun SCXW42879288 BCX8">logs</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span>
    - <span class="TextRun Highlight SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">TCP </span><span class="NormalTextRun SCXW42879288 BCX8">Listen Port for </span><span class="NormalTextRun SCXW42879288 BCX8">Zscaler</span><span class="NormalTextRun SCXW42879288 BCX8"> Internet Access Firewall Logs </span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span>
    - <span class="TextRun Highlight SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">TCP </span><span class="NormalTextRun SCXW42879288 BCX8">Listen Port for </span><span class="NormalTextRun SCXW42879288 BCX8">Z</span><span class="NormalTextRun SCXW42879288 BCX8">scaler</span><span class="NormalTextRun SCXW42879288 BCX8"> Internet Access Tunnel Logs</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span>
    - <span class="TextRun Highlight SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">TCP </span><span class="NormalTextRun SCXW42879288 BCX8">Listen Port for </span><span class="NormalTextRun SCXW42879288 BCX8">Zscaler</span><span class="NormalTextRun SCXW42879288 BCX8"> Internet Access Web Logs</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span>

</div></div>**<span class="TextRun Highlight SCXW42879288 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-parastyle="CyTech Heading 1">Collect </span><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-parastyle="CyTech Heading 1">Zscaler</span><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-parastyle="CyTech Heading 1"> Internet Access logs via </span><span class="NormalTextRun SCXW42879288 BCX8" data-ccp-parastyle="CyTech Heading 1">HTTP Endpoint</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"134245418":true,"134245529":true,"201341983":0,"335559738":240,"335559739":0,"335559740":360}"> </span>**

<div class="SCXW42879288 BCX8" id="bkmrk-listen-address---the-1" style="padding-left: 40px;"><div class="ListContainerWrapper SCXW42879288 BCX8" style="padding-left: 40px;">  
</div><div class="ListContainerWrapper SCXW42879288 BCX8">1. 1. <span class="TextRun Highlight SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Listen Address</span><span class="NormalTextRun SCXW42879288 BCX8"> - </span><span class="NormalTextRun SCXW42879288 BCX8">The bind address to listen for http endpoint connections</span><span class="NormalTextRun SCXW42879288 BCX8">.</span></span>
    2. <span class="TextRun Highlight SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">Types: </span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span>

</div><div class="ListContainerWrapper SCXW42879288 BCX8" style="padding-left: 40px;">- - <span class="TextRun Highlight SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">TCP Listen Port for </span><span class="NormalTextRun SCXW42879288 BCX8">Zscaler</span><span class="NormalTextRun SCXW42879288 BCX8"> Internet Access DNS </span><span class="NormalTextRun SCXW42879288 BCX8">logs</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span>
    - <span class="TextRun Highlight SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">TCP Listen Port for </span><span class="NormalTextRun SCXW42879288 BCX8">Zscaler</span><span class="NormalTextRun SCXW42879288 BCX8"> Internet Access Firewall Logs </span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span>
    - <span class="TextRun Highlight SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">TCP Listen Port for </span><span class="NormalTextRun SCXW42879288 BCX8">Zscaler</span><span class="NormalTextRun SCXW42879288 BCX8"> Internet Access Tunnel Logs</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span>
    - <span class="TextRun Highlight SCXW42879288 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW42879288 BCX8">TCP Listen Port for </span><span class="NormalTextRun SCXW42879288 BCX8">Zscaler</span><span class="NormalTextRun SCXW42879288 BCX8"> Internet Access Web Logs</span></span><span class="EOP SCXW42879288 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span>

</div></div>