Hey Folkes
Ingesting ZPA logs in Splunk using the Zscaler LSS service, I believe the configuration is correct based on the documentation, however the sourcetype is coming up as sc4s fallback and the logs are unreadable.
It's confirmed that the logs are streaming to the HF.
Can anyone who've done a similar configuration setup advise?
Please can I check what port configuration you have in SC4S? Have you set your port with SC4S_LISTEN_ZSCALER_LSS_TCP_PORT ? (For more info on setup please see https://splunk.github.io/splunk-connect-for-syslog/1.90.1/sources/Zscaler/ but you may have already seen this!
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing
SC4S and not S4cs, apologies for the typo.