Skip to content

Zscaler ZIA

You can integrate Zscaler ZIA with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

Zscaler ZIA product overview

Zscaler ZIA is an SSE (Security Service Edge) platform. ZIA monitors the cloud and provides a central location for software and database updates, policy and configuration settings, and threat intelligence.

What we ingest

Sophos XDR collects Zscaler ZIA data via syslog, streamed from Zscaler's Nanolog Streaming Service (NSS) in CEF format to a Sophos XDR data collector. The following NSS feeds are collected:

  • Web logs: ZIA web access and URL transactions, including web threats and policy actions.
  • Firewall logs: ZIA firewall activity and security events.
  • DNS logs: ZIA DNS query activity and security events.

Event and data types

All Zscaler ZIA records are normalized uniformly to third-party security alert telemetry. They include:

  • Web threats: Threats that Zscaler blocks or flags on web traffic, such as malware, intrusion prevention (IPS) detections, reputation-based blocks of malicious or phishing URLs, and sandbox detections, with the URL, action, category, and threat name.
  • Firewall and DNS events: Security-relevant firewall and DNS activity Zscaler raises across its NSS feeds.

Data provided by this integration

Data provided by Zscaler ZIA gets normalized to the following schemas:

  • thirdpartyalert

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation