# Elastic Integration with Zscaler NSS service

**URL:** <https://discuss.elastic.co/t/elastic-integration-with-zscaler-nss-service/211858>\
**Category:** SIEM\
**Tags:** elastic-stack-security\
**Created:** [December 14, 2019, 1:24am UTC](https://discuss.elastic.co/t/elastic-integration-with-zscaler-nss-service/211858 "2019-12-14T01:24:31Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mountainreef](https://avatars.discourse-cdn.com/v4/letter/m/dbc845/32.png) [@mountainreef](https://discuss.elastic.co/u/mountainreef)\
**Post date:** [December 14, 2019, 1:24am UTC](https://discuss.elastic.co/t/elastic-integration-with-zscaler-nss-service/211858/1 "2019-12-14T01:24:31Z")

</div>

Hi,

New here so apologies if this has been asked before? Has anyone integrated their stack with Zscalers Nanolog or NSS service for SIEM? If so is there any beats advice for connectivity, normalisation or community rules?

Zscalers website talks a lot about integrations with Splunk, Qradar, SUMO Logic etc but I cannot find anything on there regarding whether it is just a syslog forwarder or something specific that is needed.

Any help is really appreciated.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 11, 2020, 3:32am UTC](https://discuss.elastic.co/t/elastic-integration-with-zscaler-nss-service/211858/2 "2020-01-11T03:32:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![Dain.Perkins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dain.perkins/32/41143_2.png) [@Dain.Perkins](https://discuss.elastic.co/u/Dain.Perkins)\
**Post date:** [January 18, 2020, 4:38am UTC](https://discuss.elastic.co/t/elastic-integration-with-zscaler-nss-service/211858/3 "2020-01-18T04:38:00Z")

</div>

@mountainreef,

I haven't used ZScalar with Elastic, but I did use logstash at a previous gig to pull in logs with a couple of clients. IIRC it was a syslog input, but I don't have access to the configs anymore. Are you able to look at the configuration in the Zscalar gui?

My suggestion would be to get the logging setup with logstash, write it to a text file and then you can decide if logstash, filebeats, ingest pipelines, or other mechanisms would be best for the ingest.

If you get some log examples feel free to post here and we can give you some suggestions on parsing, and converting to ECS format to work with the SIEM (there a webinar coming up February 20th on this exact topic, tho I'll be using Meraki as an example)

Thanks  
/d
