All Apps and Add-ons

Zscaler Addon and Splunk Cloud: Do they require a TCP input to accept alerts from Zscaler?

ytenenbaum_splu
Splunk Employee
Splunk Employee

I am having an interesting discussion with a client here regarding Splunk Cloud and the ZScaler app/add-on, as it is something they deem as critical (given current issues they are having), and we have an app/add-on for it. While both are supported on Cloud according to Splunkbase, after going through docs it appears that they require a TCP input to accept alerts from ZScaler. I thought that wasn’t permitted with cloud environments?

Do we approach this as opening a TCP input and firewalling it to specific source IP’s? Or do we approach this as it cannot be done with the cloud environment and requires a local UF in a DMZ that will forward the data up to the cloud for processing?

0 Karma
1 Solution

ytenenbaum_splu
Splunk Employee
Splunk Employee

They just need a HF next to their internal NSS server which we can listen to and forward onto Cloud.

Watch the 3 min video. It’s around 1 minute in.

https://help.zscaler.com/zia/about-nanolog-streaming-service

So customers need to purchase and deploy the NSS product:

https://help.zscaler.com/zia/about-nanolog-streaming-service
https://www.zscaler.com/resources/data-sheets/zscaler-nanolog-streaming-service.pdf

Communication is encrypted between zScaler cloud and a customer’s NSS VM. It is only syslog/tcp from NSS -> Splunk, which by this point, is within their internal network (or this could be within a DMZ, …etc).

View solution in original post

ytenenbaum_splu
Splunk Employee
Splunk Employee

They just need a HF next to their internal NSS server which we can listen to and forward onto Cloud.

Watch the 3 min video. It’s around 1 minute in.

https://help.zscaler.com/zia/about-nanolog-streaming-service

So customers need to purchase and deploy the NSS product:

https://help.zscaler.com/zia/about-nanolog-streaming-service
https://www.zscaler.com/resources/data-sheets/zscaler-nanolog-streaming-service.pdf

Communication is encrypted between zScaler cloud and a customer’s NSS VM. It is only syslog/tcp from NSS -> Splunk, which by this point, is within their internal network (or this could be within a DMZ, …etc).

Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...