Transcription of Zscaler and Splunk | Deployment Guide
1 BUSINESS DEVELOPMENT GUIDEFEBRUARY 2023, VERSION AND Splunk Deployment GUIDE2 2023 Zscaler , Inc. All rights reserved. Zscaler AND Splunk Deployment GUIDEC ontentsTerms and Acronyms 6 About This Document 7 Zscaler Overview 7 Splunk Overview 7 Audience 7 Software Versions 7 Request for Comments 8 Zscaler and Splunk Introduction 9 ZIA Overview 9 ZPA Overview 9 Zscaler Resources 10 Splunk Cloud Overview 10 Splunk SOAR Overview 10 Splunk Resources 10 Application Architecture 11 Data models 11 Zscaler log streams 12 Web and Tunnel Logs 12 Firewall and DNS logs 13 Private Access logs 13
2 Zscaler APIs 14 Python SDK 14 Sandbox 14 Audit Logs 16 Zscaler Technical Add-on 17 Sourcetypes 17 Macros 17 Splunk CIM 18 Modular Inputs 183 2023 Zscaler , Inc. All rights reserved. Zscaler AND Splunk Deployment GUIDEZ scaler Splunk App 19 Dependencies 19 User Interface 19 Overview and Connections 20 Access Control 21 Threat Prevention 22 Private Access 23 Installation and Configuration 24 Zscaler Configuration 24 Output Strings 24 Splunk Configuration 28 Search Head 28 Forwarders (or Indexers) 28 Network Inputs 29 Modular Inputs 31 Macro Modification 31 Custom Field Mapping 32 Appendix A: Splunk Configs 33 Event Types, Tags and Aliases 33 Appendix B.
3 Splunk Essential Configuration (Using NSS VM -Stream Syslog Over TCP) 42 Configure Zscaler NSS 42 Add or Create Index 42 Log into Splunk Instance 42 Configure New Index in Splunk 43 Add Zscaler Index in Splunk 44 Create Data Inputs 45 Splunk Connect for Syslog 45 TCP Data Input 45 Select the Desired Zscaler Source Type 45 Change Default App Context and Default index 46 Verify Incoming Logs 47 Inspect Log Fields 47 Extracted Log Fields 48 Verify Splunk s Zscaler App 484 2023 Zscaler , Inc. All rights reserved. Zscaler AND Splunk Deployment GUIDEA ppendix C: Splunk Essential Configuration (using Cloud-to-Cloud logging - HTTPS POST)
4 50 Configure Splunk Cloud to Ingest ZIA Logs over HEC Input 50 Log into Splunk Cloud Tenant 51 Install Zscaler App and Zscaler TA in Your Cloud Tenant 51 Create Zscaler Index in Splunk 52 Add Zscaler Index in Splunk 52 Create a new Data Input and HEC token 54 Configure Data Input and HEC token 55 Copy the HEC Token Value 59 Determine the Splunk Cloud API Endpoint to Send Logs To 59 Configure Splunk Cloud IDM to Fetch Zscaler Audit Logs and Sandbox Events 60 Log into Splunk IDM Instance 61 Install Zscaler Splunk TA on Splunk IDM Instance 61 Configure Zscaler Index on Splunk IDM Instance 62 Add Zscaler Account Used by Splunk IDM to Make API Calls to ZIA 62 Configure Input for Audit Logs 63 Fill in the Settings for Fetching ZIA Audit Logs 64 Configure Input for Sandbox Events 64 Fill in the Settings for Fetching ZIA Sandbox Events 65 Confirm that Both Input Settings are Saved and Enabled 65 Configure Zscaler for Cloud-to-Cloud Logging 65 Navigate to Cloud-to-Cloud Logging Section in ZIA Portal 66 Setup the Cloud NSS Log Feed (Web) 66 Setup the Cloud NSS Log Feed (Firewall) 69 Add Other Log Sourcetypes 70 Validate NSS Cloud Configuration 71 Verify Splunk s Zscaler App 72 Appendix D.
5 Using SOAR (formerly Phantom) with Zscaler and Splunk 73 SOAR components 73A Sample Playbook to Showcase Zscaler and SOAR Integration 73 Configuring SOAR 75 Create new Event Label in SOAR 75 Create Automation User in SOAR 76 Installing Zscaler App on SOAR 77 Search for Zscaler App 775 2023 Zscaler , Inc. All rights reserved. Zscaler AND Splunk Deployment GUIDEC onfigure Zscaler App 78 Test Connectivity Between SOAR and Zscaler 79 Installing Splunk App on SOAR 80 Search for Splunk App 80 Configure Splunk App 81 Test connectivity Between SOAR and Splunk 83 Download Zscaler Playbook 83 Edit the playbook settings 84 Configuring Splunk 85 Install Splunk ES App 85 Manage Threat Intelligence within ES App 86 Notable Events and Forwarding to SOAR 88 Install SOAR App 90 Configure Automation User 91 Verify Events in SOAR 92 Inspect Actions Taken by SOAR 93 Appendix E.
6 Zscaler Posture Control and Splunk 94 Create AWS S3 Bucket 94 Configuring ZPC to Send Alerts to AWS S3 95 Configuring AWS 97 Configuring Splunk 100 Appendix F: Requesting Zscaler Support 103 Save Company ID 103 Enter Support Section 104 Zscaler AND Splunk Deployment GUIDE6 2023 Zscaler , Inc. All rights reserved. Terms and AcronymsThis table defines abbreviations used in the Deployment Guide . When applicable, a Request for Change (RFC) is included in the Definition column for your Programming InterfaceCACentral Authority ( Zscaler )CIMC ommon Information Model ( Splunk defined data model)CSVC omma-Separated ValuesDLPData Loss PreventionDNSD omain Name ServiceDPDDead Peer Detection (RFC 3706)GREG eneric Routing Encapsulation (RFC2890)ICMPI nternet Control Message ProtocolIKEI nternet Key Exchange (RFC2409)IPSI ntrusion Prevention SystemIPSecInternet Protocol Security (RFC2411)
7 LSSLog Streaming ServiceNSSN anolog Streaming ServiceNOCN etwork Operations CentrePACP rogrammable Automation ControllerPFSP erfect Forward SecrecyPSKPre-Share KeySaaSSoftware as a ServiceSIEMS ecurity Incident and Event ManagementSOARS ecurity Orchestration and AutomationSOCS ecurity Operations CentreSSLS ecure Socket Layer (RFC6101)TCP InputMethod of ingesting data in Splunk via TCP datagramsTLST ransport Layer SecurityVDIV irtual Desktop InfrastructureXFFX-Forwarded-For (RFC7239)ZCPZ scaler Cloud Protection ( Zscaler )ZDXZ scaler Digital Experience ( Zscaler )ZIAZ scaler Internet Access ( Zscaler )ZENZ scaler Enforcement Node ( Zscaler )Z PAZscaler Private Access ( Zscaler ) Zscaler AND Splunk Deployment GUIDE7 2023 Zscaler , Inc.
8 All rights reserved. About This DocumentThe following sections describe the organizations and requirements for the integration covered by this Deployment OverviewZscaler (NASDAQ: ZS) enables the world s leading organizations to securely transform their networks and applications for a mobile and cloud-first world. Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) services create fast, secure connections between users and applications, regardless of device, location, or network. Zscaler delivers its services 100% in the cloud and offers the simplicity, enhanced security, and improved user experience that traditional appliances or hybrid solutions can t match.
9 Used in more than 185 countries, Zscaler operates a massive, global cloud security platform that protects thousands of enterprises and government agencies from cyberattacks and data loss. For more information, go to on Zscaler , see Zscaler 's website or follow Zscaler on Twitter Splunk OverviewSplunk (NASDAQ: SPLK) is a world leader in data analytics, security incident management, orchestration and automation. Zscaler traffic, status and access logs provide a rich and voluminous source of data for ingesting into the Splunk platform. This information can then be used to enrich other data sources and generate interesting events related to business services and technology operations.
10 For more information, see Splunk 's Guide is for network administrators, endpoint and IT administrators, and security analysts responsible for deploying, monitoring, and managing enterprise security systems. This document is targeted and those interested in learning details of how Zscaler and Splunk interact, as well as providing guidance for integration of Zscaler and Splunk . This can consist of: Enterprise, Solution and Security Architects SOC and NOC designers and managers Splunk designers, implementors, administrators, and operators Anyone with a general interest in Zscaler SIEM integration and reference materialsPlease note that appendices have been added for those needing a foundational exposure to Splunk and NSS as it relates to this integration.