Zscaler Integration
Zscaler Internet Access and Private Access log ingestion for network threat detection.
What this integration does
Zscaler meets agentic SOC
Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) generate rich logs covering web traffic, DNS queries, firewall events, and private application access. ManySignal ingests Zscaler logs via the Nanolog Streaming Service (NSS) or Cloud NSS, correlating network telemetry with identity and endpoint signals to detect data exfiltration, C2 communication, and shadow IT.
ZIA web access log ingestion via NSS or Cloud NSS
ZPA private application access event collection
DNS log ingestion for threat hunting and C2 detection
Data collected
- Web transaction logs (URL, category, bytes transferred, user, device)
- DNS request and response logs with threat classification
- Firewall session logs (source, destination, protocol, action)
- ZPA access logs (user, application, connector, session duration)
- DLP policy violations and file transfer events
Actions supported
- Block user at Zscaler policy level via API on verdict
- Add URL/domain to custom block list
- Quarantine device from ZPA private app access
- Trigger ZIA policy change via API
Getting started
Set up in minutes
- 1
Configure Nanolog Streaming Service (NSS)
- 2
Configure ZPA App Connector logs
- 3
Add the connector in ManySignal
- 4
Configure DNS log analysis
Zscaler Integration: frequently asked questions
Does ManySignal support both ZIA and ZPA?
Yes. ManySignal has separate sub-connectors for ZIA (web proxy, firewall, DNS) and ZPA (private access sessions). Both can be enabled simultaneously.
What is NSS and is it required?
Nanolog Streaming Service (NSS) is Zscaler's log streaming appliance for ZIA. It is required for on-premises NSS deployments. Cloud NSS is the SaaS alternative available on Business and Transformation subscription bundles.
Can ManySignal detect data exfiltration via Zscaler?
Yes. ManySignal detects large outbound transfers to cloud storage, personal email, or file sharing services in ZIA web logs. DLP policy matches are also ingested for correlation.
How are Zscaler private apps in ZPA monitored?
ZPA access logs show which user, from which device, accessed which private application. ManySignal detects anomalous access (new device, off-hours, unusual data volume) and correlates with identity events.
Does ManySignal support Zscaler's threat intelligence classifications?
Yes. ZIA logs include Zscaler's threat category and URL category classifications. ManySignal uses these as additional signal in its detection models.
Can I alert on shadow IT discovered via Zscaler?
Yes. Zscaler Cloud Application visibility data (from SSL inspection) identifies sanctioned vs. unsanctioned applications. ManySignal alerts on access to unsanctioned cloud apps, particularly those handling sensitive data categories.
How does this integrate with endpoint data?
Zscaler Client Connector (ZCC) device identity information is included in ZIA logs. ManySignal correlates these device identifiers with CrowdStrike or SentinelOne endpoint events for full device context.
What log volume should I expect from Zscaler?
Zscaler can generate very high log volumes (millions of events per day for large organisations). ManySignal's ingestion pipeline handles this at scale and applies intelligent sampling for detection-relevant events.
Does ManySignal support the Zscaler Deception module?
Zscaler Deception events can be ingested via the same NSS stream. ManySignal treats deception alerts as high-fidelity signals and correlates them with the triggering user's other activity.
Can ManySignal act on Zscaler events without human approval?
Yes. Configure autonomous response policies in ManySignal to add user-specific URL block rules in ZIA when a high-confidence C2 or exfiltration detection fires. All autonomous actions are logged with evidence.
Related integrations
Amazon Web Services Integration
Integration
Aws Cloudtrail Integration
Integration
Aws Guardduty Integration
Integration
Aws Security Hub Integration
Integration
Aws Config Integration
Integration
Aws Vpc Flow Logs Integration
Integration
Microsoft Azure Integration
Integration
Azure Activity Logs Integration
Integration
Microsoft Entra Id Integration
Integration
Microsoft Defender Integration
Integration
Microsoft Defender For Cloud Integration
Integration
Microsoft Defender For Identity Integration
Integration
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.