Fortinet black logo

External Systems Configuration Guide

Zscaler Cloud Firewall

Zscaler Cloud Firewall

FortiSIEM Support Added: 6.1.0

Vendor: Zscaler

Product Information: https://www.zscaler.com/products

What is Discovered and Monitored

The following protocols are used to discover and monitor various aspects of Zscaler's cloud firewall.

Protocol

Metrics Collected

Used For

Syslog

Security and Compliance

Event Types

In ADMIN > Device Support > Event Types, search for "zscaler" to see the event types associated with this device.

Rules

There are no specific rules available for Zscaler, however the event categorization may match generic FortiSIEM Rules regarding traffic.

Reports

There are no specific reports for Zscaler, however the event categorization may match generic FortiSIEM Rules regarding traffic.

Configuration

Configure Zscaler to send logs to FortiSIEM. For more information, see https://help.zscaler.com/deception/how-forward-logs-syslog-server

Sample Events

"Sat Jan 01 01:01:01 2022","example","HTTP","192.0.2.0/","Allowed","General Browsing","General Browsing","123","321","78","78","General Surfing","Miscellaneous","Miscellaneous or Unknown","Clean Transaction","None","0","None","None","Example","Default Department","198.51.100.0","192.0.2.0","head","403 - Forbidden","example ua","None"

Zscaler Cloud Firewall

FortiSIEM Support Added: 6.1.0

Vendor: Zscaler

Product Information: https://www.zscaler.com/products

What is Discovered and Monitored

The following protocols are used to discover and monitor various aspects of Zscaler's cloud firewall.

Protocol

Metrics Collected

Used For

Syslog

Security and Compliance

Event Types

In ADMIN > Device Support > Event Types, search for "zscaler" to see the event types associated with this device.

Rules

There are no specific rules available for Zscaler, however the event categorization may match generic FortiSIEM Rules regarding traffic.

Reports

There are no specific reports for Zscaler, however the event categorization may match generic FortiSIEM Rules regarding traffic.

Configuration

Configure Zscaler to send logs to FortiSIEM. For more information, see https://help.zscaler.com/deception/how-forward-logs-syslog-server

Sample Events

"Sat Jan 01 01:01:01 2022","example","HTTP","192.0.2.0/","Allowed","General Browsing","General Browsing","123","321","78","78","General Surfing","Miscellaneous","Miscellaneous or Unknown","Clean Transaction","None","0","None","None","Example","Default Department","198.51.100.0","192.0.2.0","head","403 - Forbidden","example ua","None"