ZPA Application Access Logs in Splunk

In the ZPA Application Access Logs that flow in to Splunk under sourcetype=“zscalerlss-zpa-app”, I can capture the Username but how to capture the User’s hostname. I don’t see any field that captures the User’s hostname.

Thank you


Have you enabled the hostname collection and do you see it on your ZSCALER portal logs?