> For the complete documentation index, see [llms.txt](https://help.radiantsecurity.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.radiantsecurity.ai/radiant-connectors/network-security/zscaler/zscaler-nss-on-prem.md).

# ZScaler NSS On-Prem

Zscaler is a cloud security platform that proxies user and branch traffic to enforce secure web gateway, firewall, DNS, and data loss prevention policies against external and insider threats. Connecting Zscaler NSS forwards web, firewall, DNS, tunnel, SaaS security, and DLP logs to Radiant Security over syslog. Radiant uses these logs to extract artifacts during Enrichment and to answer triage questions about user behavior, destination reputation, and data movement.

Zscaler NSS can forward syslog to Radiant Security in two ways:

* **Through the Radiant Agent (recommended).** Forward to a Radiant Agent deployed in your environment.
* **Direct to Radiant Security.** Forward to a Radiant-hosted syslog endpoint. Use only when a Radiant Agent is not available.

### Prerequisites

* [ ] Admin access to Zscaler
* [ ] A deployed NSS server in your environment. See Zscaler's [Adding NSS Servers](https://help.zscaler.com/zia/adding-nss-servers) documentation, and contact Zscaler support for sizing and deployment guidance
* [ ] For the Radiant Agent path: a deployed [Radiant Agent](https://help.radiantsecurity.ai/radiant-connectors/data-connectors/install-the-radiant-security-agent) reachable from the NSS server
* [ ] For the direct path: outbound TCP egress from the NSS server to the Radiant Security syslog endpoint

### Add the data connector in Radiant Security

{% tabs %}
{% tab title="Radiant Agent (recommended)" %}

1. Log in to [Radiant Security](https://app.radiantsecurity.ai/).
2. From the navigation menu, select **Settings** > **Data Connectors**, then click **+ Add Connector**.
3. Search for and select **Radiant Agent**, then click **Data Feeds**.
4. Under **Select your data feeds**, select **ZScaler NSS On-Prem** and click **Credentials**.
5. In the **Credential Name** field, enter an identifiable name for the Radiant Agent integration (for example, `Radiant Agent integration`). To reuse an existing Radiant Agent credential, select it from the drop-down menu.
6. In the **Connector tag** field, enter any string. Radiant uses this value as salt when generating the authentication token for your connector.
7. Click **Add Connector**.
8. Open the newly created connector. Under **Vendor Configuration**, copy and save the **Token** value, then click **Download File** to download the SSL certificate and custom log format templates. You will need all three when configuring the NSS server.
9. Click **Done** to save your changes.
   {% endtab %}

{% tab title="Direct syslog" %}

1. Log in to [Radiant Security](https://app.radiantsecurity.ai/).
2. From the navigation menu, select **Settings** > **Data Connectors**, then click **+ Add Connector**.
3. Search for and select **Zscaler NSS (syslog)**, then click **Data Feeds**.
4. Under **Select your data feeds**, select **ZScaler NSS On-Prem** and click **Credentials**.
5. In the **Credential Name** field, enter an identifiable name for this credential (for example, `Zscaler NSS Credentials`).
6. In the **Connector tag** field, enter any string. Radiant uses this value as salt when generating the authentication token for your connector.
7. Click **Add Connector**.
8. Open the newly created connector. Under **Vendor Configuration**, copy and save the **Token**, then click **Download File** to download the SSL certificate and custom log format templates. You will need all three when configuring the NSS server.
9. Click **Done** to save your changes.
   {% endtab %}
   {% endtabs %}

### Configure Zscaler NSS to forward syslog through the Radiant Agent

Create one NSS feed in Zscaler for each log type you want Radiant to triage. The feed-specific parameters are listed in the NSS feed parameters by log type table at the end of this article.

{% stepper %}
{% step %}

#### Open the NSS Feed configuration

Log in to the Zscaler admin portal and go to **Administration** > **Nanolog Streaming Service** > **NSS Feed**.
{% endstep %}

{% step %}

#### Add a new NSS feed

Click **Add NSS Feed**.
{% endstep %}

{% step %}

#### Configure the feed

Enter the following values, using the per-log-type parameters from the table at the end of this article where indicated:

* **Feed Name**: a recognizable name prefixed with `radiantSecurity_` (for example, `radiantSecurity_WebLogs`).
* **NSS Server**: select the NSS server you deployed.
* **NSS Type**: see the parameters table for the value matching your log type.
* **SIEM Destination Type**: **IP** or **FQDN** of the Radiant Agent.
* **SIEM TCP Port**: the port configured on the Radiant Agent to receive Zscaler NSS data. If you do not know the port, contact your Customer Success representative.
* **SIEM Rate**: **Unlimited**.
* **Log Type**: select **Web Log**.
* **Feed Output Type**: select **Custom**.
* **Feed Escape Character**: `,\"`
* **Feed Output Format**: paste the format for this log type from the **Custom Templates** file you downloaded during the Radiant connector setup.

{% hint style="info" %}
**Note:** TCP is the recommended syslog transport. Use UDP only when TCP is not available in your environment.
{% endhint %}
{% endstep %}

{% step %}

#### Save the feed

Click **Save**.
{% endstep %}

{% step %}

#### Repeat for each log type

Repeat the previous steps for every log type listed in the parameters table you want Radiant to triage.
{% endstep %}

{% step %}

#### Activate the feeds

In the Zscaler admin portal, click **Activation** in the left-side menu, then click **Activate** to deploy your changes.

&#x20;![](/files/XKih3pjnb3yzvqVGIdaf)
{% endstep %}
{% endstepper %}

### Configure Zscaler NSS to forward syslog directly to Radiant Security

Use this path only when a Radiant Agent is not available.

Create one NSS feed in Zscaler for each log type you want Radiant to triage. The feed-specific parameters are listed in the NSS feed parameters by log type table at the end of this article.

{% stepper %}
{% step %}

#### Install the Radiant SSL certificate on the NSS server

Import the SSL certificate you downloaded from the Radiant connector into the NSS server's trusted certificate store. For the import procedure, see Zscaler's [Adding NSS Servers](https://help.zscaler.com/zia/adding-nss-servers) documentation.&#x20;
{% endstep %}

{% step %}

#### Open the NSS Feed configuration

Log in to the Zscaler admin portal and go to **Administration** > **Nanolog Streaming Service** > **NSS Feed**.
{% endstep %}

{% step %}

#### Add a new NSS feed

Click **Add NSS Feed**.
{% endstep %}

{% step %}

#### Configure the feed

Enter the following values, using the per-log-type parameters from the table at the end of this article where indicated:

* **Feed Name**: a recognizable name prefixed with `radiantSecurity_` (for example, `radiantSecurity_WebLogs`).
* **NSS Server**: select the NSS server you deployed.
* **NSS Type**: see the parameters table for the value matching your log type.
* **SIEM Destination Type**: **IP** or **FQDN** of the local Syslog Forwarder
* **SIEM TCP Port**: `514`.
* **SIEM Rate**: **Unlimited**.
* **Log Type**: select **Web Log**.
* **Feed Output Type**: select **Custom**.
* **Feed Escape Character**: `,\"`
* **Feed Output Format**: paste the format for this log type from the **Custom Templates** file you downloaded during the Radiant connector setup.
  {% endstep %}

{% step %}

#### Save the feed

Click **Save**.
{% endstep %}

{% step %}

#### Repeat for each log type

Repeat the previous steps for every log type listed in the parameters table you want Radiant to triage.
{% endstep %}

{% step %}

#### Activate the feeds

In the Zscaler admin portal, click **Activation** in the left-side menu, then click **Activate** to deploy your changes.
{% endstep %}
{% endstepper %}

#### NSS feed parameters by log type

| Log type                    | NSS Type         | Additional parameters                                   |
| --------------------------- | ---------------- | ------------------------------------------------------- |
| Web Logs                    | NSS for Web      | Log Type: Web Log                                       |
| Firewall Logs               | NSS for Firewall | Log Domain: Firewall; Firewall Log Type: Aggregate Logs |
| DNS Logs                    | NSS for Firewall | Log Domain: Firewall                                    |
| Tunnel Logs                 | NSS for Web      | Record Type: Tunnel Event                               |
| SaaS Security Logs          | NSS for Web      | Application Category: select all applicable categories  |
| SaaS Security Activity Logs | NSS for Web      | None                                                    |
| Endpoint DLP Logs           | NSS for Web      | None                                                    |
| Email DLP Logs              | NSS for Web      | None                                                    |

### Verify ingestion

After Zscaler NSS On-Prem begins forwarding, confirm alerts and events are reaching Radiant.

1. In Radiant, navigate to [Log Management](https://app.radiantsecurity.ai/logs).
2. Filter by `rs_connectorType:"zscaler_nss"`.
3. Confirm recent alerts and events appear.

{% hint style="info" %}
Allow several minutes for alerts and events to be parsed, indexed, and available for search.
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.radiantsecurity.ai/radiant-connectors/network-security/zscaler/zscaler-nss-on-prem.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
