Configure ZScaler NSS custom log formats log forwarding to Radiant Security.
Overview
In this guide, you will create custom log formats for ZScaler NSS log configuration. This is required in order to send ZScaler ZPA logs to Radiant Security without the use of an intermediary syslog relay server. These custom log formats will be provided by Radiant Security and are specific to your configuration.
To do this, you’ll need to complete the following steps:
- Add the data connector in Radiant Security
- Configure a local Radiant Security Syslog Forwarder
- Deploy the NSS server
- Set up NSS integration with Radiant Security
Add the data connector in Radiant Security
|
Configure a local Radiant Security Syslog Forwarder
Refer to the Deploy a Radiant Security Syslog Collector guide to set up a local Radiant Syslog Forwarder.
Deploy the NSS server
Please refer to ZScaler's official documentation on how to add NSS servers. You'll also need to contact the ZScaler support team for instructions on how to deploy the NSS server on your environment. The support team will calculate the appropriate resources for your NSS server.
Set up NSS integration with Radiant Security
Some log types have specific parameters, please refer to the table at the end of this section to verify those parameters.
- Log in to the ZScaler admin portal and go to the Administration > Nanolog streaming service > NSS Feed section.
- Click Add NSS Feed and enter the following information:
- Enter the feed name, preferably with the
radiantSecurity_
prefix to easily identify the feed. - Select NSS for Web in the NSS Type field.
- Select an NSS server from the drop-down menu.
- Select the SIEM destination type:
- IP or FQDN of the local Syslog Forwarder
- SIEM TCP Port: 514
- For SIEM Rate, select Unlimited.
- For Log Type, select Web Log.
- For Feed Output Type, select Custom
- Feed Escape Character: ,\”
- Feed Output Format:
- Paste the format according to the log type selected. The custom formats can be found on the Custom Templates file that you downloaded during the Radiant Security data connector set up.
- Click Save.
- Enter the feed name, preferably with the
- Repeat step 2 for each log type listed in the table below. Some log types require additional parameters, as indicated in the table.
Log Type Parameters Web Logs - NSS Type: NSS for Web
Firewall Logs - NSS Type: NSS for Firewall
- Log Domain: Firewall
- Firewall Log Type: Aggregate Logs
DNS Logs - Log Domain: Firewall
Tunnel Logs - NSS Type: NSS for Web
- Record Type: Tunnel Event
SaaS Security Logs - NSS Type: NSS for Web
- Application Category: Select all the application categories that apply
SaaS Security Activity Logs - NSS Type: NSS for Web
Endpoint DLP Logs - NSS Type: NSS for Web
Email DLP Logs - NSS Type: NSS for Web
We value your opinion. Did you find this article helpful? Share your thoughts by clicking here or reach to our Product and Customer Success teams at support@radiantsecurity.ai
Last updated: 2025-01-14