All Apps and Add-ons

Zscaler Addon and Splunk Cloud: Do they require a TCP input to accept alerts from Zscaler?

ytenenbaum_splu
Splunk Employee
Splunk Employee

I am having an interesting discussion with a client here regarding Splunk Cloud and the ZScaler app/add-on, as it is something they deem as critical (given current issues they are having), and we have an app/add-on for it. While both are supported on Cloud according to Splunkbase, after going through docs it appears that they require a TCP input to accept alerts from ZScaler. I thought that wasn’t permitted with cloud environments?

Do we approach this as opening a TCP input and firewalling it to specific source IP’s? Or do we approach this as it cannot be done with the cloud environment and requires a local UF in a DMZ that will forward the data up to the cloud for processing?

0 Karma
1 Solution

ytenenbaum_splu
Splunk Employee
Splunk Employee

They just need a HF next to their internal NSS server which we can listen to and forward onto Cloud.

Watch the 3 min video. It’s around 1 minute in.

https://help.zscaler.com/zia/about-nanolog-streaming-service

So customers need to purchase and deploy the NSS product:

https://help.zscaler.com/zia/about-nanolog-streaming-service
https://www.zscaler.com/resources/data-sheets/zscaler-nanolog-streaming-service.pdf

Communication is encrypted between zScaler cloud and a customer’s NSS VM. It is only syslog/tcp from NSS -> Splunk, which by this point, is within their internal network (or this could be within a DMZ, …etc).

View solution in original post

ytenenbaum_splu
Splunk Employee
Splunk Employee

They just need a HF next to their internal NSS server which we can listen to and forward onto Cloud.

Watch the 3 min video. It’s around 1 minute in.

https://help.zscaler.com/zia/about-nanolog-streaming-service

So customers need to purchase and deploy the NSS product:

https://help.zscaler.com/zia/about-nanolog-streaming-service
https://www.zscaler.com/resources/data-sheets/zscaler-nanolog-streaming-service.pdf

Communication is encrypted between zScaler cloud and a customer’s NSS VM. It is only syslog/tcp from NSS -> Splunk, which by this point, is within their internal network (or this could be within a DMZ, …etc).

Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...