vpn.zscaler
Introduction
The tags beginning with vpn.zscaler
identify events generated by Zscaler Client Connector.
Valid tags and data tables
The full tag must have three levels. The first two are fixed as vpn.zscaler
. The third level identifies the type of events sent.
Product/Service | Tags | Data table |
---|---|---|
Zscaler |
|
|
|
| |
|
| |
|
|
For more information, read more About Devo tags.
Table structure
vpn.zscaler.access
Field | Type | Extra fields | Field transformation | Source field name |
---|---|---|---|---|
eventdate |
| Â | Â | Â |
hostname |
| Â | Â | Â |
LogTimestamp |
| Â | parsedate(replace(LogTimestamp_tmp, " ", " "), dateformat("ddd MMM DD HH:mm:ss YYYY", "UTC")) Â | LogTimestamp_tmp |
ConnectionID |
| Â | Â | Â |
Exporter |
| Â | Â | Â |
TimestampRequestReceiveStart |
| Â | Â | Â |
TimestampRequestReceiveHeaderFinish |
| Â | Â | Â |
TimestampRequestReceiveFinish |
| Â | Â | Â |
TimestampRequestTransmitStart |
| Â | Â | Â |
TimestampRequestTransmitFinish |
| Â | Â | Â |
TimestampResponseReceiveStart |
| Â | Â | Â |
TimestampResponseReceiveFinish |
| Â | Â | Â |
TimestampResponseTransmitStart |
| Â | Â | Â |
TimestampResponseTransmitFinish |
| Â | Â | Â |
TotalTimeRequestReceive |
| Â | Â | Â |
TotalTimeRequestTransmit |
| Â | Â | Â |
TotalTimeResponseReceive |
| Â | Â | Â |
TotalTimeResponseTransmit |
| Â | Â | Â |
TotalTimeConnectionSetup |
| Â | Â | Â |
TotalTimeServerResponse |
| Â | Â | Â |
Method |
| Â | Â | Â |
Protocol |
| Â | Â | Â |
Host |
| Â | Â | Â |
URL |
| Â | Â | Â |
UserAgent |
| Â | Â | Â |
XFF |
| Â | Â | Â |
NameID |
| Â | Â | Â |
StatusCode |
| Â | Â | Â |
RequestSize |
| Â | Â | Â |
ResponseSize |
| Â | Â | Â |
ApplicationPort |
| Â | Â | Â |
ClientPublicIp |
| Â | Â | Â |
ClientPublicPort |
| Â | Â | Â |
ClientPrivateIp |
| Â | Â | Â |
Customer |
| Â | Â | Â |
ConnectionStatus |
| Â | Â | Â |
ConnectionReason |
| Â | Â | Â |
hostchain |
| ✓ |  |  |
tag |
| ✓ |  |  |
rawMessage |
| ✓ |  |  |
vpn.zscaler.activity
Field | Type | Extra fields | Field transformation | Source field name |
---|---|---|---|---|
eventdate |
| Â | Â | Â |
hostname |
| Â | Â | Â |
LogTimestamp |
| Â | parsedate(replace(LogTimestamp_tmp, " ", " "), dateformat("ddd MMM DD HH:mm:ss YYYY", "UTC")) Â | LogTimestamp_tmp |
Customer |
| Â | Â | Â |
SessionID |
| Â | Â | Â |
ConnectionID |
| Â | Â | Â |
InternalReason |
| Â | Â | Â |
ConnectionStatus |
| Â | Â | Â |
IPProtocol |
| Â | Â | Â |
DoubleEncryption |
| Â | Â | Â |
Username |
| Â | Â | Â |
ServicePort |
| Â | Â | Â |
ClientPublicIP |
| Â | Â | Â |
ClientPrivateIP |
| Â | Â | Â |
ClientLatitude |
| Â | Â | Â |
ClientLongitude |
| Â | Â | Â |
ClientCountryCode |
| Â | Â | Â |
ClientZEN |
| Â | Â | Â |
Policy |
| Â | Â | Â |
Connector |
| Â | Â | Â |
ConnectorZEN |
| Â | Â | Â |
ConnectorIP |
| Â | Â | Â |
ConnectorPort |
| Â | Â | Â |
Host_str |
| Â | Â | Â |
Host |
| Â | ifthenelse(Host_str -> '.', ip4(Host_str), null) Â | Host_str |
Application |
| Â | Â | Â |
AppGroup |
| Â | Â | Â |
Server |
| Â | Â | Â |
ServerIP |
| Â | Â | Â |
ServerPort |
| Â | Â | Â |
PolicyProcessingTime |
| Â | Â | Â |
CAProcessingTime |
| Â | Â | Â |
ConnectorZENSetupTime |
| Â | Â | Â |
ConnectionSetupTime |
| Â | Â | Â |
ServerSetupTime |
| Â | Â | Â |
AppLearnTime |
| Â | Â | Â |
TimestampConnectionStart |
| Â | Â | Â |
TimestampConnectionEnd |
| Â | Â | Â |
TimestampCATx |
| Â | Â | Â |
TimestampCARx |
| Â | Â | Â |
TimestampAppLearnStart |
| Â | Â | Â |
TimestampZENFirstRxClient |
| Â | Â | Â |
TimestampZENFirstTxClient |
| Â | Â | Â |
TimestampZENLastRxClient |
| Â | Â | Â |
TimestampZENLastTxClient |
| Â | Â | Â |
TimestampConnectorZENSetupComplete |
| Â | Â | Â |
TimestampZENFirstRxConnector |
| Â | Â | Â |
TimestampZENFirstTxConnector |
| Â | Â | Â |
TimestampZENLastRxConnector |
| Â | Â | Â |
TimestampZENLastTxConnector |
| Â | Â | Â |
ZENTotalBytesRxClient |
| Â | Â | Â |
ZENBytesRxClient |
| Â | Â | Â |
ZENTotalBytesTxClient |
| Â | Â | Â |
ZENBytesTxClient |
| Â | Â | Â |
ZENTotalBytesRxConnector |
| Â | Â | Â |
ZENBytesRxConnector |
| Â | Â | Â |
ZENTotalBytesTxConnector |
| Â | Â | Â |
ZENBytesTxConnector |
| Â | Â | Â |
Idp |
| Â | Â | Â |
NAplication |
| Â | Â | Â |
NApGroup |
| Â | Â | Â |
TimestampNApLearnStart |
| Â | Â | Â |
ClientToClient |
| Â | Â | Â |
hostchain |
| ✓ |  |  |
tag |
| ✓ |  |  |
rawMessage |
| ✓ |  |  |
vpn.zscaler.status_connector
Field | Type | Extra fields | Field transformation | Source field name |
---|---|---|---|---|
eventdate |
| Â | Â | Â |
hostname |
| Â | Â | Â |
LogTimestamp |
| Â | Â | LogTimestamp_tmp |
Customer |
| Â | Â | Â |
SessionID |
| Â | Â | Â |
SessionType |
| Â | Â | Â |
SessionStatus |
| Â | Â | Â |
Version |
| Â | Â | Â |
Platform |
| Â | Â | Â |
ZEN |
| Â | Â | Â |
Connector |
| Â | Â | Â |
ConnectorGroup |
| Â | Â | Â |
PrivateIP |
| Â | Â | Â |
PublicIP |
| Â | Â | Â |
Latitude |
| Â | Â | Â |
Longitude |
| Â | Â | Â |
CountryCode |
| Â | Â | Â |
TimestampAuthentication |
| Â | Â | Â |
TimestampUnAuthentication |
| Â | Â | Â |
CPUUtilization |
| Â | Â | Â |
MemUtilization |
| Â | Â | Â |
ServiceCount |
| Â | Â | Â |
InterfaceDefRoute |
| Â | Â | Â |
DefRouteGW |
| Â | Â | Â |
PrimaryDNSResolver |
| Â | Â | Â |
HostUpTime |
| Â | Â | Â |
ConnectorUpTime |
| Â | Â | Â |
NumOfInterfaces |
| Â | Â | Â |
BytesRxInterface |
| Â | Â | Â |
PacketsRxInterface |
| Â | Â | Â |
ErrorsRxInterface |
| Â | Â | Â |
DiscardsRxInterface |
| Â | Â | Â |
BytesTxInterface |
| Â | Â | Â |
PacketsTxInterface |
| Â | Â | Â |
ErrorsTxInterface |
| Â | Â | Â |
DiscardsTxInterface |
| Â | Â | Â |
TotalBytesRx |
| Â | Â | Â |
TotalBytesTx |
| Â | Â | Â |
hostchain |
| ✓ |  |  |
tag |
| ✓ |  |  |
rawMessage |
| ✓ |  |  |
vpn.zscaler.status_user
Field | Type | Extra fields | Field transformation | Source field name |
---|---|---|---|---|
eventdate |
| Â | Â | Â |
hostname |
| Â | Â | Â |
LogTimestamp |
| Â | Â | LogTimestamp_tmp |
Customer |
| Â | Â | Â |
Username |
| Â | Â | Â |
SessionID |
| Â | Â | Â |
SessionStatus |
| Â | Â | Â |
Version |
| Â | Â | Â |
ZEN |
| Â | Â | Â |
CertificateCN |
| Â | Â | Â |
PrivateIP |
| Â | Â | Â |
PublicIP |
| Â | Â | Â |
Latitude |
| Â | Â | Â |
Longitude |
| Â | Â | Â |
CountryCode |
| Â | Â | Â |
TimestampAuthentication |
| Â | Â | Â |
TimestampUnAuthentication |
| Â | Â | Â |
TotalBytesRx |
| Â | Â | Â |
TotalBytesTx |
| Â | Â | Â |
Idp |
| Â | Â | Â |
Hostname |
| Â | Â | Â |
Platform |
| Â | Â | Â |
ClientType |
| Â | Â | Â |
TrustedNetworks |
| Â | Â | Â |
TrustedNetworksNames |
| Â | Â | Â |
SAMLAttributes |
| Â | Â | Â |
PosturesHit |
| Â | Â | Â |
PosturesMisses |
| Â | Â | Â |
ZENLatitude |
| Â | Â | Â |
ZENLongitude |
| Â | Â | Â |
ZENCountryCode |
| Â | Â | Â |
hostchain |
| ✓ |  |  |
tag |
| ✓ |  |  |
rawMessage |
| ✓ |  |  |