All Apps and Add-ons

Zscaler Addon and Splunk Cloud: Do they require a TCP input to accept alerts from Zscaler?

ytenenbaum_splu
Splunk Employee
Splunk Employee

I am having an interesting discussion with a client here regarding Splunk Cloud and the ZScaler app/add-on, as it is something they deem as critical (given current issues they are having), and we have an app/add-on for it. While both are supported on Cloud according to Splunkbase, after going through docs it appears that they require a TCP input to accept alerts from ZScaler. I thought that wasn’t permitted with cloud environments?

Do we approach this as opening a TCP input and firewalling it to specific source IP’s? Or do we approach this as it cannot be done with the cloud environment and requires a local UF in a DMZ that will forward the data up to the cloud for processing?

0 Karma
1 Solution

ytenenbaum_splu
Splunk Employee
Splunk Employee

They just need a HF next to their internal NSS server which we can listen to and forward onto Cloud.

Watch the 3 min video. It’s around 1 minute in.

https://help.zscaler.com/zia/about-nanolog-streaming-service

So customers need to purchase and deploy the NSS product:

https://help.zscaler.com/zia/about-nanolog-streaming-service
https://www.zscaler.com/resources/data-sheets/zscaler-nanolog-streaming-service.pdf

Communication is encrypted between zScaler cloud and a customer’s NSS VM. It is only syslog/tcp from NSS -> Splunk, which by this point, is within their internal network (or this could be within a DMZ, …etc).

View solution in original post

ytenenbaum_splu
Splunk Employee
Splunk Employee

They just need a HF next to their internal NSS server which we can listen to and forward onto Cloud.

Watch the 3 min video. It’s around 1 minute in.

https://help.zscaler.com/zia/about-nanolog-streaming-service

So customers need to purchase and deploy the NSS product:

https://help.zscaler.com/zia/about-nanolog-streaming-service
https://www.zscaler.com/resources/data-sheets/zscaler-nanolog-streaming-service.pdf

Communication is encrypted between zScaler cloud and a customer’s NSS VM. It is only syslog/tcp from NSS -> Splunk, which by this point, is within their internal network (or this could be within a DMZ, …etc).

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...