<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Zscaler app in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Zscaler-app/m-p/758501#M23902</link>
    <description>&lt;P&gt;Thank you Paul. You motivated me.&lt;/P&gt;</description>
    <pubDate>Thu, 19 Feb 2026 11:18:07 GMT</pubDate>
    <dc:creator>Splunk_adm</dc:creator>
    <dc:date>2026-02-19T11:18:07Z</dc:date>
    <item>
      <title>Zscaler app</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Zscaler-app/m-p/758499#M23900</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We want to integrate Splunk with Zscaler, and according to the documentation, the following components are required for full integration:&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;UL&gt;&lt;LI&gt;The Zscaler Splunk App&lt;/LI&gt;&lt;LI&gt;Zscaler Technical Add-On (TA)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The problem is that Zscaler is managed by another team, and we do not have an administrative account there.&lt;/P&gt;&lt;P&gt;Is it possible to fully integrate Splunk ↔ Zscaler without having an account in Zscaler?&lt;BR /&gt;In such a situation, do we only have the option to receive “raw logs”?&lt;/P&gt;&lt;P&gt;Thank you in advance for the information and your help.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 19 Feb 2026 10:18:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Zscaler-app/m-p/758499#M23900</guid>
      <dc:creator>Splunk_adm</dc:creator>
      <dc:date>2026-02-19T10:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: Zscaler app</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Zscaler-app/m-p/758500#M23901</link>
      <description>&lt;P&gt;Based on the official documentation&amp;nbsp;&lt;A href="https://help.zscaler.com/downloads/zscaler-technology-partners/operations/zscaler-and-splunk-deployment-guide/Zscaler-Splunk-Deployment-Guide-FINAL.pdf" target="_blank"&gt;Zscaler and Splunk Deployment Guide&lt;/A&gt;&amp;nbsp;the TA contains some modular inputs to pull logs from the zscaler API endpoints. For these inputs you need a API user from the Zscaler team.&lt;/P&gt;&lt;P&gt;Zscaler NSS and LSS streams can be pushed directly from Zscaler to Splunk. So for this kind of data you don't need any Zscaler account but the configuration must be done on Zscaler side to push the data.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Feb 2026 11:07:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Zscaler-app/m-p/758500#M23901</guid>
      <dc:creator>PaulPanther</dc:creator>
      <dc:date>2026-02-19T11:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: Zscaler app</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Zscaler-app/m-p/758501#M23902</link>
      <description>&lt;P&gt;Thank you Paul. You motivated me.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Feb 2026 11:18:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Zscaler-app/m-p/758501#M23902</guid>
      <dc:creator>Splunk_adm</dc:creator>
      <dc:date>2026-02-19T11:18:07Z</dc:date>
    </item>
  </channel>
</rss>

