Zscaler
Zscaler normalises Zscaler events and enables
you to analyse Zscaler data using reports and
pre-set dashboard views.
Bug Fix
PLUG-17747
Zscaler admin audit logs in the documented
Zscaler: <component>: log_ts=... format were not normalised. As a result, the component and event timestamp were not captured, and normalised logs used the ingestion time instead of the actual event time.
Past Releases
Zscaler v5.2.0▾
Enhancements
KB-22739
Added Syslog Collector based Zscaler log source template, simplifying the log source configuration process. To learn more, go to Creating Log Source via a Template.
KB-15588
Updated ZscalerCompiledNormalizer to support new and old format Zscaler logs.
KB-20267
Modularized the ZscalerCompiledNormalizer to support Nanolog Streaming Service Firewall, Web, AdminAudit, SaasSecurity, Tunnel and Domain Name System logs.
Bug Fixes
KB-16516, KB-16842, KB-18569, KB-19332
Some ZScaler logs were not normalized
by ZscalerCompiledNormalizer and LP_Zscaler.
KB-20242
Some Zscaler Firewall logs were not properly parsed by ZscalerCompiledNormalizer.
Zscaler v5.1.0▾
Bug Fix
KB-11462
An issue in the normalization package LP_Zscalar and compiled normalizer ZscalarCompiledNormalizer, where insufficient log validation resulted in the incorrect normalization of logs from other sources and some Zscalar logs has now been resolved.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.