Send all policy configuration changes to Splunk

What is required to get started on sending alerts from Zscaler on Splunk regarding policy configuration changes / audit logs.
I am fairly new to this and planning to get this sorted for one of my clients.

Hi Arnab,
You should be able to select Admin Audit as an NSS output feed. If you feed into the Zsaler Splunkbase App, there’s a tab at the top for admin audit.

Warm Regards,
Chris