About the Integration:
Zscaler and Cribl help security teams turn high-volume Zero Trust telemetry into cleaner, more actionable data flows for SIEMs, security data lakes, and analytics platforms. Cribl ingests Zscaler data through Cloud NSS over HTTPS or VM-based NSS streaming, then shapes, enriches, de-duplicates, and routes that data to wherever that creates the most value. The result is better cost control, broader retention, and faster investigations without forcing teams to send every event to a single expensive destination.
Benefits:
Reduce SIEM and storage costs by filtering, shaping, and tiering Zscaler logs before delivery downstream.
Route one Zscaler data stream to multiple tools, including SIEM, long-term storage, and search workflows.
Improve detections and investigations with enriched, de-duplicated signals instead of repetitive raw events.
Retain more Zscaler history cost-effectively in Cribl Lake and replay only the data needed for deeper analysis.
How to Get Data Flowing:
Choose your Zscaler delivery model first: use Cloud NSS for HTTPS-based cloud-to-cloud delivery, or NSS VM if you need VM-based streaming into your environment.
Configure a Cribl source to receive the feed, and make sure the required listener is reachable from Zscaler over HTTPS for Cloud NSS or the appropriate TCP path for NSS VM.
Create the Zscaler feed in the Zscaler admin console, using JSON when possible and the correct API endpoint, token, or destination details from Cribl.
Apply Cribl pipelines to normalize fields, enrich context, remove duplicates, and route high-value events to SIEM while sending broader data sets to lower-cost storage or lake targets.
Verify events are arriving with expected timestamps and structure, then confirm downstream routing to your security and analytics tools.
Monitor volume and recovery behavior after go-live, because Cloud NSS and NSS buffering are time-bound and very low rate limits or broken connectivity can lead to dropped logs.