Before you start

Before starting this procedure, you must have:

  1. An SIEM that Expel supports for this integration, which includes any 1 of the following:
  • The Nanolog Streaming Service (NSS) from Zscaler to forward data to your SIEM.
  • Step 1: Send Zscaler events to a SIEM

    The Nanolog Streaming Service (NSS) feed specifies the data from the logs that the NSS sends to the SIEM. Expel uses 3 NSS feeds to forward data to a SIEM.

    Screen Shot 2021-03-08 at 8.04.01 AM.png

    1. The EXPEL_MALWARE feed captures any malware class events.  
        • Feed Output Type : QRadar LEEF
        • Web Log Filters = Security > Malware Classes : Sandbox, Spyware, Virus
        • Feed Output Format =
        • %s{mon} %02d{dd} %02d{hh}:%02d{mm}:%02d{ss} zscaler-EXPEL_MALWARE: LEEF:1.0|Zscaler|NSS|4.1|fqdn=%s{host}\turl=%s{url}\tmethod=%s{reqmethod}\tuser_agent=%s{ua}\turlclass=%s{urlclass}\tcategory=%s{urlcat}\treferrer=%s{referer}\tresponse=%s{respcode}\tprotocol=%s{proto}\tduration_ms=%d{ctime}\tsrc=%s{cip}\tdst=%s{sip}\tbytes_rx=%d{respsize}\tbytes_tx=%d{reqsize}\tappclass=%s{appclass}\tappname=%s{appname}\tflow_id=%d{recordid}\torganization=%s{dept}\tusername=%s{login}\tvendor_version=%s{productversion}\tname=%s{reason}\talert_at=%s{time}%s{tz}\talertaction=%s{action}\tfile_hash=%s{bamd5}\tmime_type=%s{filetype}\tfilename=%s{filename}\tscore=%d{riskscore}\trealm=%s{location}\tnsssvcip=%s{nsssvcip}\tthreatname=%s{threatname}\tmalwarecategory=%s{malwarecat}\tmalwareclass=%s{malwareclass}\t\n
    2. The EXPEL_THREAT feed surfaces any Advanced Threat events.
        • Feed Output Type : QRadar LEEF
        • Web Log Filters = Security > Advanced Threats : Adware/Spyware Sites, Botnet Callback, Browser  Exploit, Cross-site Scripting, Cryptomining, Malicious Content, Other Threat, Peer-to-Peer, Phishing, Spyware Callback, Suspicious Content, Suspicious Destination, Unauthorized Communication, Web Spam
        • Feed Output Format = 
        • %s{mon} %02d{dd} %02d{hh}:%02d{mm}:%02d{ss} zscaler-EXPEL_THREAT: LEEF:1.0|Zscaler|NSS|4.1|fqdn=%s{host}\turl=%s{url}\tmethod=%s{reqmethod}\tuser_agent=%s{ua}\turlclass=%s{urlclass}\tcategory=%s{urlcat}\treferrer=%s{referer}\tresponse=%s{respcode}\tprotocol=%s{proto}\tduration_ms=%d{ctime}\tsrc=%s{cip}\tdst=%s{sip}\tbytes_rx=%d{respsize}\tbytes_tx=%d{reqsize}\tappclass=%s{appclass}\tappname=%s{appname}\tflow_id=%d{recordid}\torganization=%s{dept}\tusername=%s{login}\tvendor_version=%s{productversion}\tname=%s{reason}\talert_at=%s{time}%s{tz}\talertaction=%s{action}\tfile_hash=%s{bamd5}\tmime_type=%s{filetype}\tfilename=%s{filename}\tscore=%d{riskscore}\trealm=%s{location}\tnsssvcip=%s{nsssvcip}\tthreatname=%s{threatname}\tmalwarecategory=%s{malwarecat}\tmalwareclass=%s{malwareclass}\t\n
    3. (Optional) You can add an additional feed, EXPEL_INVESTIGATE, to forward all web log data to your SIEM. Expel analysts use this information to understand, scope, and answer security questions related to threat behavior. Specifically, how it got there, what it is, and what must be done to remediate.
      • Feed Output Type : QRadar LEEF  
      • Web Log Filters = None  
      • Feed Output Format = 
      • %s{mon} %02d{dd} %02d{hh}:%02d{mm}:%02d{ss} zscaler-EXPEL_INVESTIGATE: LEEF:1.0|Zscaler|NSS|4.1|fqdn=%s{host}\turl=%s{url}\tmethod=%s{reqmethod}\tuser_agent=%s{ua}\turlclass=%s{urlclass}\tcategory=%s{urlcat}\treferrer=%s{referer}\tresponse=%s{respcode}\tprotocol=%s{proto}\tduration_ms=%d{ctime}\tsrc=%s{cip}\tdst=%s{sip}\tbytes_rx=%d{respsize}\tbytes_tx=%d{reqsize}\tappclass=%s{appclass}\tappname=%s{appname}\tflow_id=%d{recordid}\torganization=%s{dept}\tusername=%s{login}\tvendor_version=%s{productversion}\tname=%s{reason}\talert_at=%s{time}%s{tz}\talertaction=%s{action}\tfile_hash=%s{bamd5}\tmime_type=%s{filetype}\tfilename=%s{filename}\tscore=%d{riskscore}\trealm=%s{location}\tnsssvcip=%s{nsssvcip}\tthreatname=%s{threatname}\tmalwarecategory=%s{malwarecat}\tmalwareclass=%s{malwareclass}\t\n

    Step 2: Configure the technology in Workbench

    Now that we have the correct access configured and events are being sent to a SIEM, we can integrate Zscaler with Expel.

    Register Zscaler in Expel Workbench

    1. In a new browser tab, log into https://workbench.expel.io/settings/security-devices?setupIntegration=zscaler
    2. Complete the following fields in Workbench:
      mceclip1.png
        • Select the SIEM (this device should already be brought onboard to Workbench).
        • Type the Name and Location of the device.
        • For SIEM index, type the name of the SIEM index that Zscaler events are being indexed to. 
    3. Click Save.

    Related keywords

    z scaler