Zscaler ZIA
You can integrate Zscaler ZIA with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Zscaler ZIA product overview
Zscaler ZIA is an SSE (Security Service Edge) platform. ZIA monitors the cloud and provides a central location for software and database updates, policy and configuration settings, and threat intelligence.
What we ingest
Sophos XDR collects Zscaler ZIA data via syslog, streamed from Zscaler's Nanolog Streaming Service (NSS) in CEF format to a Sophos XDR data collector. The following NSS feeds are collected:
- Web logs: ZIA web access and URL transactions, including web threats and policy actions.
- Firewall logs: ZIA firewall activity and security events.
- DNS logs: ZIA DNS query activity and security events.
Event and data types
All Zscaler ZIA records are normalized uniformly to third-party security alert telemetry. They include:
- Web threats: Threats that Zscaler blocks or flags on web traffic, such as malware, intrusion prevention (IPS) detections, reputation-based blocks of malicious or phishing URLs, and sandbox detections, with the URL, action, category, and threat name.
- Firewall and DNS events: Security-relevant firewall and DNS activity Zscaler raises across its NSS feeds.
Data provided by this integration
Data provided by Zscaler ZIA gets normalized to the following schemas:
thirdpartyalert
For more information about using schemas in Data Lake Search, see Schemas and logical types.