Forum Discussion
SteveCombs
Apr 23, 2019Copper Contributor
MCAS Help with ZSCaler
I recently implemented Cloud App Security with a ZSCaler instance. I am getting the logs to come over into MCAS, but when they are doing so, they user ID is coming anonymized. I have checked in MC...
Eli Shlomo
Jul 22, 2019MVP
Does the issue still occur?
- SteveCombsJul 22, 2019Copper Contributor
It turns out that the source for ZScaler data needs to be NSS. It is hard coded into the MCAS software.
- Danny KadyshevitchJul 30, 2019Former EmployeeThat is incorrect. Data source name (i.e. NSS) isn't hardcoded in MCAS, and can be modified in Zscaler 'zbridge-mcas.properties' file.
- Eli ShlomoJul 22, 2019MVPthere are main settings for zscaler for mcas: NSS The source with zscaler QRadar LEEF The receiver type = Syslog - UDP and for your issue is the anonymize private information. I work with zscaler and mcas together and it does a great job.