Zscaler Cloud Firewall
FortiSIEM Support Added: 6.1.0
Vendor: Zscaler
Product Information: https://www.zscaler.com/products
What is Discovered and Monitored
The following protocols are used to discover and monitor various aspects of Zscaler's cloud firewall.
Protocol |
Metrics Collected |
Used For |
---|---|---|
Syslog |
|
Security and Compliance |
Event Types
In ADMIN > Device Support > Event Types, search for "zscaler" to see the event types associated with this device.
Rules
There are no specific rules available for Zscaler, however the event categorization may match generic FortiSIEM Rules regarding traffic.
Reports
There are no specific reports for Zscaler, however the event categorization may match generic FortiSIEM Rules regarding traffic.
Configuration
Configure Zscaler to send logs to FortiSIEM. For more information, see https://help.zscaler.com/deception/how-forward-logs-syslog-server
Sample Events
"Sat Jan 01 01:01:01 2022","example","HTTP","192.0.2.0/","Allowed","General Browsing","General Browsing","123","321","78","78","General Surfing","Miscellaneous","Miscellaneous or Unknown","Clean Transaction","None","0","None","None","Example","Default Department","198.51.100.0","192.0.2.0","head","403 - Forbidden","example ua","None"