Skip to content

Integrate Zscaler ZIA

You can integrate Zscaler ZIA with Sophos XDR so that it sends data to Sophos for analysis. The integration uses a data collector, which receives third-party data and sends it to the Sophos Data Lake.

Key steps

The key steps in a Zscaler ZIA integration are as follows:

  • Install and configure a data collector if you haven't already done so.
  • Create a Zscaler Nanolog Streaming Service (NSS) server.
  • Configure your Zscaler NSS device to forward firewall, web, and DNS logs to the Sophos XDR data collector.

Requirements

The following is required for Zscaler ZIA configuration:

  • An administrator account in the Zscaler NSS web administration interface.
  • Check the requirements for the data collector you're using by reviewing the guides at Data collectors.

Add a Zscaler ZIA integration

To integrate Zscaler ZIA, you must first install a Sophos XDR data collector, then configure a Zscaler Nanolog Streaming Service (NSS) server and set it up to forward firewall, web, and DNS to Sophos XDR.

Install and configure a data collector

Zscaler ZIA must be configured to send logs to the Sophos XDR data collector. Logs are filtered and correlated in real-time for various security event observations. Go to Data collectors and follow the guide for creating a data collector if you haven't already done so.

Configure an NSS server

To configure an NSS server, do as follows:

  1. Sign in to the Zscaler NSS web administration interface.
  2. Go to Administration > Settings > Nanolog Streaming Service.
  3. Follow the steps to size the NSS device. For more information, see this Zscaler training video: What to Know: Nanolog Streaming Service.
  4. Click Add NSS Server.
  5. Enter a name to identify this as an NSS server for streaming events to Sophos.
  6. In Type, select NSS for Web or NSS for Firewall.

    Tip

    We recommend deploying instances of both NSS for Web and NSS for Firewall. This ensures that you capture all relevant alert types. In most cases, you should deploy these on-premises so you can forward syslog to the Sophos XDR data collector in your environment.

  7. Set Status to Enabled.

  8. Click Save.
  9. Download and deploy the image to your platform, such as VMware or AWS.

Tip

For more information about NSS devices, see the following documents:

Next, configure NSS to forward each type of logs you want.

Forward firewall logs

To configure Zscaler NSS to send firewall logs, do as follows:

  1. Sign in to the Zscaler NSS web administration interface.
  2. Click Administration > Settings > Nanolog Streaming Service.
  3. Click the NSS Feeds tab.
  4. Click Add NSS Feed.
  5. In Edit NSS Feed, configure these settings:

    • Feed Name: Enter a name for the feed.
    • NSS Type: Select NSS for Firewall.
    • NSS Server: Select your NSS for Firewall server.
    • Status: Click Enabled.
    • SIEM IP Address: Enter your Sophos XDR data collector's server IP address.
    • SIEM TCP Port: Enter 514.
    • Log Type: Click Firewall Logs.
    • Firewall Log Type: Click Both Session and Aggregate Logs.
    • Feed Output Type: Select Custom.
    • Feed Output Format: Copy and enter the following string:

      %s{mon} %02d{dd} %02d{hh}:%02d{mm}:%02d{ss} zscaler-nss-fw CEF:0|Zscaler|NSSFWlog|5.7|%s{action}|%s{rulelabel}|3| act=%s{action} suser=%s{login} src=%s{csip} spt=%d{csport} dst=%s{cdip} dpt=%d{cdport} deviceTranslatedAddress=%s{ssip} deviceTranslatedPort=%d{ssport} destinationTranslatedAddress=%s{sdip} destinationTrans latedPort=%d{sdport} sourceTranslatedAddress=%s{tsip} sourceTranslatedPort=%d{tsport} proto=%s{ipproto} tunnelType=%s{ttype} dnat=%s{dnat} stateful=%s{stateful} spriv=%s{location} reason=%s{rulelabel} in=%ld{inbytes} out=%ld{outbytes} deviceDirection=1 cs1=%s{dept} cs1Label=dept cs2=%s{nwsvc} cs2Label=nwService cs3=%s{nwapp} cs3Label=nwApp cs4=%s{aggregate} cs4Label=aggregated cs5=%s{threatcat} cs5Label=threatcat cs6=%s{threatname} cs6label=threatname cn1=%d{durationms} cn1Label=durationms cn2=%d{numsessions} cn2Label=numsessions cs5Label=ipCat cs5=%s{ipcat} destCountry=%s{destcountry} avgduration=%d{avgduration}\n
      
    • Duplicate Logs: Select Disabled.

  6. For the remaining fields, keep the default values.

  7. Click Save.

Forward web logs

To configure Zscaler NSS to send web logs, do as follows:

  1. Sign in to the Zscaler NSS web administration interface.
  2. Click Administration > Settings > Nanolog Streaming Service.
  3. Click the NSS Feeds tab.
  4. Click Add NSS Feed.
  5. In Edit NSS Feed, configure these settings:

    • Feed Name: Enter a name for the feed.
    • NSS Server: Select your NSS for Web server.
    • Status: Click Enabled.
    • SIEM IP Address: Enter your Sophos XDR data collector's server IP address.
    • SIEM TCP Port: Enter 514.
    • Log Type: Click Web Log.
    • Feed Output Type: Copy and enter the following string:

      %s{mon} %02d{dd} %02d{hh}:%02d{mm}:%02d{ss} zscaler-nss CEF:0|Zscaler|NSSWeblog|5.7|%s{action}|%s{reason}|3| act=%s{action} reason=%s{reason} app=%s{proto} dhost=%s{ehost} dst=%s{sip} src=%s{cip} sourceTranslatedAddress=%s{cintip} in=%d{respsize} out=%d{reqsize} request=%s{eurl} requestContext=%s{ereferer} outcome=%s{respcode} requestClientApplication=%s{ua} requestMethod=%s{reqmethod} suser=%s{login} spriv=%s{location} externalId=%d{recordid} fileType=%s{filetype} destinationServiceNam e=%s{appname} cat=%s{urlcat} deviceDirection=1 cn1=%d{riskscore} cn1Label=riskscore cs1=%s{dept} cs1Label=dept cs2=%s{urlcat} cs2Label=urlcat cs3=%s{malwareclass} cs3Label=malwareclass cs4=%s{malwarecat} cs4Label=malwarecat cs5=%s{threatname} cs5Label=threatname cs6Label=%s{bamd5} cs6=md5hash rulelabel=%s{rulelabel} ruletype=%s{ruletype} urlclass=%s{urlclass} devicemodel=%s{devicemodel}\n
      
  6. For the remaining fields, keep the default values.

  7. Click Save.

Forward DNS logs

To configure Zscaler to send DNS logs, do as follows:

  1. Sign in to the Zscaler NSS web administration interface.
  2. Click Administration > Settings > Nanolog Streaming Service.
  3. Click the NSS Feeds tab.
  4. Click Add NSS Feed.
  5. In Edit NSS Feed, configure these settings:

    • Feed Name: Enter a name for the feed.
    • NSS Type: Select NSS for Firewall.
    • NSS Server: Select one of your NSS server instances.
    • Status: Click Enabled.
    • SIEM IP Address: Enter your Sophos XDR data collector's server IP address.
    • Log Type: Click DNS Logs.
    • Feed Output Type: Select Custom.
    • Feed Output Format: Copy and enter the following string:

      %s{mon} %02d{dd} %02d{hh}:%02d{mm}:%02d{ss} zscaler-nss-fw CEF:0|Zscaler|NSSDNSlog|5.7|%s{action}|%s{rulelabel}|3| suser=%s{login} cs1=%s{dept} cs1Label=department cs2=%s{reqaction} cs2Label=reqaction cs3=%s{resaction} cs3Label=resaction cs4=%s{reqtype} cs4Label=dns_reqtype cs5=%s{req} cs5Label=dns_req cs6=%s{res} cs6Label=dns_resp cn1=%d{durationms} cn1Label=durationms flexString1=%s{reqrulelabel} flexString1Label=reqrulelabel flexString2=%s{resrulelabel} flexString2Label=resrulelabel cat=%s{domcat} src=%s{cip} dst=%s{sip} dpt=%d{sport} spriv=%s{location} suid=%s{deviceowner} dvchost=%s{devicehostname}\n
      
    • Duplicate Logs: Select Disabled.

  6. For the remaining fields, keep the default values.

  7. Click Save.

Your Zscaler ZIA data should now appear in the Sophos Data Lake after validation.

Configuration notes

Keep the following in mind during Zscaler ZIA configuration:

  • You can configure multiple instances of Zscaler to send data to Sophos via the same data collector. After you finish integration, repeat the steps in this section for your other instances of Zscaler.

Additional resources

For more information on configuring Zscaler ZIA, see the following documents: