Zscaler Deception
Integration Guide for Zscaler Deception with BluSapphire SIEM
Prerequisites
Confirm the following before starting configuration:
Requirement
Detail
Zscaler Service Connector
Zscaler Deception Admin access
Administrator login to the Zscaler Deception console.
Network access
Port open from Zscaler service connector to BluSapphire DataStreamer
Information needed
BluSapphire DataStreamer’s static private IP and port number (to be shared by BluSapphire team)
Configuration Steps
Follow the steps below to configure Zscaler Service Connector.
Log in to the NetXGATE Firewall
1.
Open a browser and navigate to the Zscaler Deception Admin Portal.
2.
Enter your Administrator credentials and log in.
Navigate to Syslog integration settings
1.
From the main menu, go to Orchestrate→ SIEM Integrations.
2.
Click Add Integration, and select Syslogfrom the drop-down menu
Edit the Syslog Details window
1.
Name: Enter a name for the Syslog SIEM integration.
2.
Enabled: Select to enable SIEM integration.
3.
Service Connector: Select a Service Connector from the drop-down menu:
4.
Type of logs: Select an option from the drop-down menu:Events: Send events to Syslog.Audit Logs: Send audit logs to Syslog.
Enter Syslog Server Details
1.
Host: Enter the BluSapphire DataStreamer’s static private IP.
2.
Port Number: Enter the UDP listener port shared by BluSapphire team.
3.
**Transport:**Select TCP
4.
Let the other settings remain as default and click Save. The Syslog server integration will then be added successfully.
To test the Syslog server integration, access a decoy and generate alerts on the Zscaler Deception dashboard.
Troubleshooting
Symptom
Likely Cause
Fix
No logs arriving at syslog server
UDP/TCP blocked by intermediate firewall or ACL
Allow traffic on chosen port from the NetXGATE IP to Datastreamer IP
Last updated