Implemented

Zscaler connector

We have moved to Zscaler for web filtering and now we are blind in terms of logs...

Parents Comment
  • Upon further inspection, it looks like the Zscaler is expecting logs in CSV format. Can you change the output type to CSV and confirm if you're then seeing the logs in LEM? There's a chance you may see unmatched data, which we can fix based on a log sample and connector update. We'll get the logs into LEM first.

Children
  • Unfortunately this is still not working. I set the feed type to CSV, refreshed the 'tool maintenance by alias' report after about 30 minutes for the last 24 hours, and no unmatched data. I have also ran an ndepth report for the connector name "zscaler" (that is the name i provided to the connector), and no results other than internal tool offline/online "started fast reader". I also have a ticket open with support, but no solution as of yet as they also wanted to see log output but all i have is the feed output format below/documented.

    pastedImage_0.png

  • Would you mind sending me your Case ID for the open support ticket?