Zscaler Private Access (ZPA)

Samurai [Local] CollectorSamurai [Cloud] Collector
Picture1.svg

Connectivity Requirements

You must ensure the following connectivity requirements are fulfilled:

SourceDestinationPortsDescription
Zscaler App ConnectorSamurai Local CollectorTCP/514For log transmission

Log Receiver Configuration

Follow the steps outlined in the ZPA documentation.

Use the following parameters when completing the steps within the documentation under section 1. Log Receiver:

Field NameParameter
NameSpecify a unique name, such as User Activity
DescriptionSpecify a relevant description
Domain or IP AddressIP address of your Samurai Local Collector
TCP Port514
TLS EncryptionDisabled
App Connector GroupsSelect the group(s) related to the on-prem App Connector(s) that will forward data to the Samurai Local Collector

Use the following parameters when completing the steps within the documentation under section 2. Log Stream:

Field NameParameter
Log TypeUser Activity
Log TemplateJSON
PolicySelect

Create Additional Log Receivers

A log receiver is required for each log type. Complete the Log Receiver Configuration steps outlined above for each log type listed below. Where User Activity is referenced in the previous section, replace it with the log types listed below:

  • Browser Access
  • Audit Logs

For integrations that utilize a Local Collector where we ingest syslog only, you do not need to follow specific steps in the Samurai MDR portal as we auto detect the vendor and product. The only reason you need to use the Samurai MDR portal is if you need to determine the Local Collector IP address. Of course you will still need to ensure the integration is functioning! See Integrations for more information on checking status.

Our Integration guide was accurate at the time of writing but vendors change things frequently! If you find errors or anything is outdated, let us know by raising a request in the Samurai MDR application and we shall get it updated.