netstat.zscaler
Introduction
The tags beginning with netstat.zscaler
identify network statistic events generated by Zscaler.
Valid tags and data tables
The full tag must have at least 3 levels. The first two are fixed as netstat.zscaler
. The third level corresponds to the product while the fourth identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product/Service | Tag | Data table |
---|---|---|
Zscaler Analyzer |
|
|
|
| |
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in these tables:
netstat.zscaler.analyzer
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
| Â | Â |
machine |
| Â | Â |
rawMessage |
|  | ✓ |
serverdate |
| Â | Â |
priority |
| Â | Â |
severity |
| Â | Â |
URL |
| Â | Â |
LoadTime |
| Â | Â |
CumTime |
| Â | Â |
newEmbeddedURL |
| Â | Â |
message |
| rawMessage | Â |
hostchain |
|  | ✓ |
tag |
|  | ✓ |
netstat.zscaler.analyzer_zpa
Field | Type | Field Transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
| Â | Â | Â |
machine |
| Â | Â | Â |
logTimestamp |
| Â | Â | Â |
Customer |
| Â | Â | Â |
SessionID |
| Â | Â | Â |
ConnectionID |
| ConnectionID_first_piece + "," + ConnectionID_secnd_piece | ConnectionID_secnd_piece ConnectionID_first_piece | Â |
InternalReason |
| Â | Â | Â |
ConnectionStatus |
| Â | Â | Â |
IPProtocol |
| Â | Â | Â |
DoubleEncryption |
| Â | Â | Â |
Username |
| Â | Â | Â |
ServicePort |
| Â | Â | Â |
ClientPublicIP |
| Â | Â | Â |
ClientPrivateIP |
| Â | Â | Â |
ClientLatitude |
| Â | Â | Â |
ClientLongitude |
| Â | Â | Â |
ClientCountryCode |
| Â | Â | Â |
ClientZEN |
| Â | Â | Â |
Policy |
| Â | Â | Â |
Connector |
| Â | Â | Â |
ConnectorZEN |
| Â | Â | Â |
ConnectorIP |
| Â | Â | Â |
ConnectorPort |
| Â | Â | Â |
Host |
| Â | Â | Â |
Application |
| Â | Â | Â |
AppGroup |
| Â | Â | Â |
Server |
| Â | Â | Â |
ServerIP |
| Â | Â | Â |
ServerPort |
| Â | Â | Â |
PolicyProcessingTime |
| Â | Â | Â |
CAProcessingTime |
| Â | Â | Â |
ConnectorZENSetupTime |
| Â | Â | Â |
ConnectionSetupTime |
| Â | Â | Â |
ServerSetupTime |
| Â | Â | Â |
AppLearnTime |
| Â | Â | Â |
TimestampConnectionStart |
| Â | Â | Â |
TimestampConnectionEnd |
| Â | Â | Â |
TimestampCATx |
| Â | Â | Â |
TimestampCARx |
| Â | Â | Â |
TimestampAppLearnStart |
| Â | Â | Â |
TimestampZENFirstRxClient |
| Â | Â | Â |
TimestampZENFirstTxClient |
| Â | Â | Â |
TimestampZENLastRxClient |
| Â | Â | Â |
TimestampZENLastTxClient |
| Â | Â | Â |
TimestampConnectorZENSetupComplete |
| Â | Â | Â |
TimestampZENFirstRxConnector |
| Â | Â | Â |
TimestampZENFirstTxConnector |
| Â | Â | Â |
TimestampZENLastRxConnector |
| Â | Â | Â |
TimestampZENLastTxConnector |
| Â | Â | Â |
ZENTotalBytesRxClient |
| Â | Â | Â |
ZENBytesRxClient |
| Â | Â | Â |
ZENTotalBytesTxClient |
| Â | Â | Â |
ZENBytesTxClient |
| Â | Â | Â |
ZENTotalBytesRxConnector |
| Â | Â | Â |
ZENBytesRxConnector |
| Â | Â | Â |
ZENTotalBytesTxConnector |
| Â | Â | Â |
ZENBytesTxConnector |
| Â | Â | Â |
Idp |
| Â | Â | Â |
message |
| Â | rawMessage | Â |
rawMessage |
|  |  | ✓ |
tag |
|  |  | ✓ |
hostchain |
|  |  | ✓ |
Â