Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 

Configuring a Syslog Feed in Zscaler NSS

 

To collect events, you must configure a log feed on your Zscaler NSS to forward syslog events to JSA.

  1. Log in to the administration portal for Zscaler NSS.
  2. Select Administration >Settings >Nanolog Streaming Service.
  3. On the NSSFeeds tab, click Add.
  4. Enter a name for the feed.
  5. On the NSSServer menu, select an NSS.
  6. Set the SIEM IP Address to the IP address of the JSA Event Collector.
  7. Set the SIEM TCP Port to port 514.
  8. Set the Feed Output Type to JSA LEEF. The Feed Output Format is automatically populated with the appropriate string:
  9. Click Save.

    JSA automatically discovers and creates a log source for Zscaler NSS appliances. Events that are forwarded to JSA are viewable on the Log Activity tab.