Hi Everyone,
We want to integrate Splunk with Zscaler, and according to the documentation, the following components are required for full integration:
The problem is that Zscaler is managed by another team, and we do not have an administrative account there.
Is it possible to fully integrate Splunk ↔ Zscaler without having an account in Zscaler?
In such a situation, do we only have the option to receive “raw logs”?
Thank you in advance for the information and your help.
Based on the official documentation Zscaler and Splunk Deployment Guide the TA contains some modular inputs to pull logs from the zscaler API endpoints. For these inputs you need a API user from the Zscaler team.
Zscaler NSS and LSS streams can be pushed directly from Zscaler to Splunk. So for this kind of data you don't need any Zscaler account but the configuration must be done on Zscaler side to push the data.
Based on the official documentation Zscaler and Splunk Deployment Guide the TA contains some modular inputs to pull logs from the zscaler API endpoints. For these inputs you need a API user from the Zscaler team.
Zscaler NSS and LSS streams can be pushed directly from Zscaler to Splunk. So for this kind of data you don't need any Zscaler account but the configuration must be done on Zscaler side to push the data.
Thank you Paul. You motivated me.