All Apps and Add-ons

Zscaler App for Splunk: What are the installation steps for this application?

Splunk_Bw
Explorer

Hello,
Can you please add some install steps to app document? Nothing was clear on app installation steps.
which port?
Index creation?
etc.

0 Karma

uthornander_spl
Splunk Employee
Splunk Employee

What would the steps be for a splunk cloud installation as the splunk cloud only accept data from a forwarder.
https://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Data/Monitornetworkports
"For security, Splunk Cloud accepts connections only from forwarders with the correct Secure Sockets Layer (SSL) certificates. If you want to send data from a TCP or UDP source such as syslog, use the Splunk Universal Forwarder to listen to the source and forward the data to your Splunk Cloud deployment."

This implies that you need a forwarder as a go-between?

UT
0 Karma

sridhar_narasim
Engager

Hi,

The Zscaler App for Splunk works in conjunction with the Nanolog Streaming Service (NSS). The documentation to integrate the NSS with Splunk is described in the NSS Admin Guide that's available on Help Portal (you can access it by logging onto the admin UI and clicking Help at the top right). Having said that, point taken on making it simpler to access the Splunk Config docs right with the app itself.

Let me know if this works out for you. Feel free to request assistance from Support (support at zscaler dot com).

Thanks,
Sridhar

slavigne
Engager

I downvoted this post because the nss config guide does not have configuration steps for the "zscaler app for splunk" it only demonstrates how to configure the nanolog streaming service to send logs via syslog in cim format. the documentation for this app is poor.

0 Karma

princemanto2580
Path Finder

Hi Sridhar, is that Admin Guide of NSS can be available from NSS Admin UI or Zscaler UI. I don't have much information on it. Appreciate for your help in advance.

0 Karma

corners
New Member

Hi, is this app compatible with Splunk version 5.0.4 ?
thanks

0 Karma

ppablo
Retired

Hi @Splunk_Bw

You might want to contact the author of the app directly for a topic like this. The contact information for the author can be found in the bottom right panel of the app's page: https://apps.splunk.com/app/1580/

Sridhar Narasimhan
sridhar@zscaler.com

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...