This article explains how to connect Zscaler Secure Internet Access (ZIA) to Workbench.
Prerequisites
Before starting this procedure, you must have:
-
A SIEM that Expel supports for this integration, which includes any one of the following:
-
Sumo Logic
Note
If you have a SIEM that's supported by Expel but isn't listed here, contact support.
-
The Nanolog Streaming Service (NSS) from Zscaler to forward data to your SIEM.
Quick Links
Step 1: Send Zscaler Events to a SIEM
The Nanolog Streaming Service (NSS) feed specifies the data from the logs that the NSS sends to the SIEM. Expel uses 3 NSS feeds to forward data to a SIEM.
-
The EXPEL_MALWARE feed captures any malware class events.
-
Feed Output Type: QRadar SIEM LEEF
-
Web Log Filters = Security > Malware Classes : Sandbox, Spyware, Virus
-
Feed Output Format =
%s{mon} %02d{dd} %02d{hh}:%02d{mm}:%02d{ss} zscaler-EXPEL_MALWARE:LEEF:1.0|Zscaler|NSS|4.1|fqdn=%s{host}\turl=%s{url}\tmethod=%s{reqmethod}\tuser_agent=%s{ua}\turlclass=%s{urlclass}\tcategory=%s{urlcat}\treferrer=%s{referer}\tresponse=%s{respcode}\tprotocol=%s{proto}\tduration_ms=%d{ctime}\tsrc=%s{cip}\tdst=%s{sip}\tbytes_rx=%d{respsize}\tbytes_tx=%d{reqsize}\tappclass=%s{appclass}\tappname=%s{appname}\tflow_id=%d{recordid}\torganization=%s{dept}\tusername=%s{login}\tvendor_version=%s{productversion}\tname=%s{reason}\talert_at=%s{time}%s{tz}\talertaction=%s{action}\tfile_hash=%s{bamd5}\tmime_type=%s{filetype}\tfilename=%s{filename}\tscore=%d{riskscore}\trealm=%s{location}\tnsssvcip=%s{nsssvcip}\tthreatname=%s{threatname}\tmalwarecategory=%s{malw arecat}\tmalwareclass=%s{malwareclass}\t\n
-
-
The EXPEL_THREAT feed surfaces any Advanced Threat events.
-
Feed Output Type: QRadar SIEM LEEF
-
Web Log Filters = Security > Advanced Threats : Adware/Spyware Sites, Botnet Callback, Browser Exploit, Cross-site Scripting, Cryptomining, Malicious Content, Other Threat, Peer-to-Peer, Phishing, Spyware Callback, Suspicious Content, Suspicious Destination, Unauthorized Communication, Web Spam
-
Feed Output Format =
%s{mon} %02d{dd} %02d{hh}:%02d{mm}:%02d{ss} zscaler-EXPEL_THREAT:LEEF:1.0|Zscaler|NSS|4.1|fqdn=%s{host}\turl=%s{url}\tmethod=%s{reqmethod}\tuser_agent=%s{ua}\turlclass=%s{urlclass}\tcategory=%s{urlcat}\treferrer=%s{referer}\tresponse=%s{respcode}\tprotocol=%s{proto}\tduration_ms=%d{ctime}\tsrc=%s{cip}\tdst=%s{sip}\tbytes_rx=%d{respsize}\tbytes_tx=%d{reqsize}\tappclass=%s{appclass}\tappname=%s{appname}\tflow_id=%d{recordid}\torganization=%s{dept}\tusername=%s{login}\tvendor_version=%s{productversion}\tname=%s{reason}\talert_at=%s{time}%s{tz}\talertaction=%s{action}\tfile_hash=%s{bamd5}\tmime_type=%s{filetype}\tfilename=%s{filename}\tscore=%d {riskscore}\trealm=%s{location}\tnsssvcip=%s{nsssvcip }\tthreatname=%s{threatname}\tmalwarecategory=%s{malw arecat}\tmalwareclass=%s{malwareclass}\t\n
-
-
(Optional) You can add an additional feed, EXPEL_INVESTIGATE, to forward all web log data to your SIEM. SOC analysts use this information to understand, scope, and answer security questions related to threat behavior. Specifically, how it got there, what it is, and what must be done to remediate.
-
Feed Output Type: QRadar SIEM LEEF
-
Web Log Filters = None
-
Feed Output Format =
%s{mon} %02d{dd} %02d{hh}:%02d{mm}:%02d{ss} zscaler-EXPEL_INVESTIGATE:LEEF:1.0|Zscaler|NSS|4.1|fqdn=%s{host}\turl=%s{url}\tmethod=%s{reqmethod}\tuser_agent=%s{ua}\turlclass=%s{urlclass}\tcategory=%s{urlcat}\treferrer=%s{referer}\tresponse=%s{respcode}\tprotocol=%s{proto}\tduration_ms=%d{ctime}\tsrc=%s{cip}\tdst=%s{sip}\tbytes_rx=%d{respsize}\tbytes_tx=%d{reqsize}\tappclass=%s{appclass}\tappname=%s{appname}\tflow_id=%d{recordid}\torganization=%s{dept}\tusername=%s{login}\tvendor_version=%s{productversion}\tname=%s{reason}\talert_at=%s{time}%s{tz}\talertaction=%s{action}\tfile_hash=%s{bamd5}\tmime_type=%s{filetype}\tfilename=%s{filename}\tscore=%d{riskscore}\trealm=%s{location}\tnsssvcip=%s{nsssvcip}\tthreatname=%s{threatname}\tmalwarecategory=%s{malwarecat}\tmalwareclass=%s{malwareclass}\t\n
-
Step 2: Configure the Technology in Workbench
-
In a new browser tab, log into https://workbench.expel.io/settings/security-devices?setupIntegration=Zscaler.
-
Complete the following fields in Workbench:
-
Select the SIEM. This device should already be onboarded in Workbench.
-
Type the Name and Location of the device.
-
For SIEM index, type the name of the SIEM index that Zscaler events are being indexed to.
-
-
You can set up console access now or use the instructions below to set it up later.