Configure ZScaler NSS Cloud HTTPS log forwarding to Radiant Security.
Overview
In this guide, you will create custom log formats for ZScaler NSS Cloud log configuration. This is required in order to send ZScaler logs to Radiant Security through HTTPS.
To do this, you’ll need to complete the following steps:
- Add the data connector in Radiant Security
- Set up NSS Cloud Integration with the Radiant Security Connector
Add the data connector in Radiant Security
Set up NSS Cloud Integration with the Radiant Security Connector
Some log types have specific parameters, please refer to the table at the end of this section to check those parameters.
- Log in to the ZScaler admin portal and go to the Administration > Nanolog streaming service > Cloud NSS Feed section.
- Click Add Cloud NSS Feed.
- Enter the following information:
- Enter the feed name, preferably with the
radiantSecurity_
prefix to easily identify the feed. - Select NSS for Web in the NSS Type field.
- Select the SIEM destination type: Other.
- For SIEM Rate, select Unlimited.
- Max Batch Size: 1024 KB
- For the API URL field, enter the Webhook URL provided during the Radiant Connector setup.
- Under HTTP Headers, add a new header with the following parameters:
- Name: rs_token
- Value: enter the Token value provided during the Radiant Connector setup
- For Log Type, select Web Log.
- For Feed Output Type, select Custom.
- Feed Escape Character: \"
- Feed Output Format:
- Paste the format according to the log type selected. The custom formats can be found on the Custom Templates file that you downloaded during the Radiant Security data connector setup.
- Set the Timezone to GMT.
- Click Save.
- Click Activate.
- Enter the feed name, preferably with the
- Repeat step 2 for each log type listed in the table below. Some log types require additional parameters, as indicated in the table.
Log Type Parameters Web Logs NSS Type: NSS for Web Firewall Logs NSS Type: NSS for Firewall
Log Domain: Firewall
Firewall Log Type: Aggregate LogsDNS Logs Log Domain: Firewall Tunnel Logs NSS Type: NSS for Web
Record Type: Tunnel EventSaaS Security Logs NSS Type: NSS for Web
Application Category: Select all the application categories that applySaaS Security Activity Logs NSS Type: NSS for Web Endpoint DLP Logs NSS Type: NSS for Web Email DLP Logs NSS Type: NSS for Web Alerts Default Settings
We value your opinion. Did you find this article helpful? Share your thoughts by clicking here or reach to our Product and Customer Success teams at support@radiantsecurity.ai
Last updated: 2025-01-12