Troubleshooting Splunk API Calls to Zscaler

Sometimes one needs to dig into the Splunk loge when Zscaler API calls are not indexing data. This is a handy command to run which reveals the internals / INFO / DEBUG calls.

"index=_internal source=*splunkd.log* (component=ModularInputs stderr) OR component=ExecProcessor"