Splunk Enterprise Security

Which Data Model are need to update if I use Zscaler add-on

princemanto2580
Path Finder

Hello All,

I used the Splunk Add-on for Zscaler (https://splunkbase.splunk.com/app/3865/). But what are the data-model need to update in order to see the events IN ES (Enterprise Security) is missing in the documentation section.

It will really great if someone can help me by sharing this information.

0 Karma

dflodstrom
Builder

Have a look at this app's tags.conf. Check out the tag combinations listed for each eventtype and compare to what is required for each CIM data model. It looks like this app tags events to match the following data models: Authentication, Network Traffic, Web, Data Loss Prevention, Intrusion Detection, Malware, Network Session, Network Resolution, and Performance.

Before rebuilding every data model you might want to check the logs you're getting to see if every eventtype is being sent to Splunk and that the logs are being parsed/tagged properly.

This app is tagging by eventtype. `[eventtype=Zscaler_DNS]
dns = enabled
network = enabled
resolution = enabled

[eventtype=Zscaler_CFW]
communicate = enabled
network = enabled

[eventtype=Zscaler_Proxy_General]
communicate = enabled
end = enabled
network = enabled
performance = enabled
proxy = enabled
session = enabled
start = enabled
web = enabled

[eventtype=Zscaler_Proxy_Malware]
attack = enabled
ids = enabled
malware = enabled

[eventtype=Zscaler_Proxy_DLP]
dlp = enabled
incident = enabled

[eventtype=Zscaler_ZPA]
authentication = enabled
communicate = enabled
end = enabled
network = enabled
performance = enabled
session = enabled
start = enabled
vpn = enabled`

The tags required for each data model are listed here http://docs.splunk.com/Documentation/CIM/4.11.0/User/Howtousethesereferencetables

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...