Zscaler Splunk App - Design and Installation documentation

Zscaler is pleased to release the attached document in conjunction with the latest version of the Zscaler Splunk App. This new versions adds some great new capabilities with Zscaler API’s being used to retrieve Admin Audit Logs (ZIA) and detailed Cloud Sandbox detonation correlation and reporting.

Splunk Design and Install.docx (3.4 MB)

The Splunk App and Technical Add-On can be downloaded from Splunk Base

Your feedback is always welcome, please feel free to comment here or contact splunk-support@zscaler.com


Can we stream the Logs directly from the Zscaler Cloud to Splunk (on-prem), or we still need a Zscaler_NSS VM to stream it to the Splunk app?
This is a on premises environment.

Yes, NSS is still required.

1 Like