Skip to main content

Zscaler NSS

Zscaler sits inline between users and the internet, so its logs are the closest thing most organisations have to a complete record of outbound web and DNS activity — including from devices that never touch the corporate network. The Nanolog Streaming Service (NSS) is how those logs leave the Zscaler cloud: an NSS feed streams them to a collector of your choosing, in a format you define.

Filed here, catalogued elsewhere

The catalog files this template under Endpoint Management rather than with the network services. Search for Zsaler NSS — the catalog spells the vendor name without the c, and the search box matches the catalog's spelling, not the correct one.

Zscaler-side Setup

Create the NSS feed in the ZIA admin portal, following Zscaler's own documentation. Two things about it matter here:

  • This template receives over HEC, so the feed must be configured for a Splunk-compatible endpoint rather than for a syslog collector.
  • The feed's field set is fixed at creation. The NSS feed template determines which fields leave the Zscaler cloud, and a feed defined with the wrong field set cannot be corrected downstream — it has to be redefined at Zscaler.

Install the Application

Go to Platform → Applications → Install Application From Template and choose Zsaler NSS from the Endpoint Management category. Both parameters are required:

ParameterNotes
datalakePre-filled managed.
datalake index namePre-filled Zscaler — correctly spelled, unlike the template name.

Setup New Zsaler NSS Application panel

Press Install. The application then appears in the Installed Applications view, where its badge reads Running once the pipeline is up.

Validating the Data

Browse to a recognisable destination from a device behind Zscaler and confirm the transaction appears in the Zscaler index. Note the delay NSS adds between the transaction and the log leaving the cloud.