I have a set up a single-node test instance of Splunk to try and ingest zScaler LSS (not NSS) logs via a TCP input. However, it is not ingesting any data, despite being able to see traffic via TCPDump on that port
I have installed the latest zScaler Splunk App (v2.0.7) and the zScaler Technical Add-on (v3.1.2)
[root@ip-10-127-0-113 apps]# ls | grep scaler
via the WebUI, I have set up a TCP input on port 10000, set the sourcetype, app and index options.
I have checked to make sure that Splunk is listening on TCP/10000 and can see that it is