AdobeStock_594228060-2

New Year, New Integrations: Cribl Stream and Zscaler Nanolog Streaming Service

Last edited: February 19, 2025

Your web transaction data has stories to tell. Important ones about threats, compliance, and operational health. But right now, those stories are probably scattered across expensive Security Event Managers (SEMs), threat analysis platforms, and various data lakes… not exactly a bestseller in the making.

As part of January 2025’s 4.10.0 release, customers can now source log data from Zscaler Nanolog Streaming Service (NSS) using the new Zscaler Cloud NSS Source. Cribl’s native integration with Zscaler NSS helps you:

  • Route critical security alerts to your Security Information and Event Management (SIEM) system for immediate action

  • Send enriched threat data to your analysis platforms

  • Archive everything else for compliance without breaking the bank

That way, you can stop paying premium SIEM prices for logs you rarely use, finally get your security and IT teams speaking the same data language, and make your threat analysts actually thank you for the quality of data they receive.

Meet Zscaler’s Nanolog Streaming Service

Zscaler’s Nanolog Streaming Service (NSS) is a log streaming service that allows customers to export security event logs. This rolls up to Zscaler’s broader platform. Zscaler accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications anywhere. Distributed across more than 150 data centers, the SSE-based Zero Trust Exchange is the world’s largest in-line cloud security platform. Learn more about Zscaler.

How-To Get Data Moving

Setting up data flow from Zscaler NSS to Cribl Stream will require action within both platforms. Before you start, ensure you have admin permissions in your Zscaler environment and Cribl Stream.

Setting up the new Zscaler Cloud NSS Source in Cribl Stream

Login to Cribl, navigate to Stream and a Worker Group. Select Data > Sources.

unnamed.png

Search or scroll to the Zscaler Cloud NSS tile. Select the tile and select Add Source.

unnamed.png

Enter an Input ID, Address, and Port. Leave the HEC Endpoint as the default value (/services/collector).

unnamed.png
  1. Select Add Token

  2. Set the Authentication Method to Manual.

  3. Select Generate.

  4. Copy the Token value.

  5. Select Save.

  6. Commit and Deploy. The Token value will be used in the following Zscaler configuration steps.

Locate and note your Worker Group Ingress Address.

unnamed.png

Within the specific Worker Group, navigate to the Overview tab. The Ingress Address is under Group Information. This will be used in the Zscaler configuration steps below.

Setting Up a Data Stream in Zscaler NSS Cloud

Login to Zscaler

unnamed.png

In the left menu, select Administration, then Nanolog Streaming Service under Cloud Configuration.

unnamed.png

Select the Cloud NSS Feeds tab. Then select +Add Cloud NSS Feed

unnamed.png

Enter in the following Cloud NSS Feed configurations:

  • Add a Feed Name

  • Select SIEM TYPE = Splunk.

  • Enter the API URL as https://default.<workspace>.<cribl_cloud_name>.cribl.cloud:<port>/services/collector

  • Add two HTTP Headers

    • Key 1 value = Authorization, Value 1= token from the Cribl Zscaler Source

    • Key 2 value = Content-Encoding, Value 2 = gzip

Continue to scroll down the NSS Cloud Feed configuration.

unnamed.png

Select Log Type. Disable JSON Array Notation. Select Save.

You will see the feed added to the Cloud NSS Feed list.

unnamed.png

Testing the Connection

In Cribl Stream, after committing and deploying, the Zscaler Source will change from a blue (no health metrics available) to a green (healthy) status icon.

unnamed.png

Under the Status column of the Source line item, select the Live button next to the green status icon.

unnamed.png

Select Capture and increase the Capture time (sec) to a large value like 100. Then select Start.

In a separate tab or window, navigate to the Cloud NSS Feed.

unnamed.png

Select the Test Connectivity icon in the far right column. You will see a success message at the top of the console.

unnamed.png

Navigate back to Cribl Stream to see the test event land successfully in the Zscaler Source!

Go Deeper

Cribl, the Data Engine for IT and Security, empowers organizations to transform their data strategy. Customers use Cribl’s suite of products to collect, process, route, and analyze all IT and security data, delivering the flexibility, choice, and control required to adapt to their ever-changing needs.

We offer free training, certifications, and a free tier across our products. Our community Slack features Cribl engineers, partners, and customers who can answer your questions as you get started and continue to build and evolve. We also offer a variety of hands-on Sandboxes for those interested in how companies globally leverage our products for their data challenges.

More from the blog

get started

Choose how to get started

See

Cribl

See demos by use case, by yourself or with one of our team.

Try

Cribl

Get hands-on with a Sandbox or guided Cloud Trial.

Free

Cribl

Process up to 1TB/day, no license required.