> For the complete documentation index, see [llms.txt](https://docs.blusapphire.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.blusapphire.io/log-forwarding/03_log-forwarding-guide/log-forward/zscaler/zscaler-deception.md).

# Zscaler Deception

Integration Guide for **Zscaler Deception** with **BluSapphire SIEM**

**Prerequisites**

Confirm the following before starting configuration:

| **Requirement**                    | **Detail**                                                                                      |
| ---------------------------------- | ----------------------------------------------------------------------------------------------- |
| **Zscaler Service Connector**      | <https://help.zscaler.com/itdr/about-service-connectors>                                        |
| **Zscaler Deception Admin access** | Administrator login to the Zscaler Deception console.                                           |
| **Network access**                 | Port open from Zscaler service connector to BluSapphire DataStreamer                            |
| **Information needed**             | BluSapphire DataStreamer’s static private IP and port number (to be shared by BluSapphire team) |

**Configuration Steps**

Follow the steps below to configure Zscaler Service Connector.

1. **Log in to the NetXGATE Firewall**

<table data-header-hidden><thead><tr><th width="80.6484375"></th><th></th></tr></thead><tbody><tr><td><strong>1.</strong></td><td>Open a browser and navigate to the Zscaler Deception Admin Portal.</td></tr><tr><td><strong>2.</strong></td><td>Enter your Administrator credentials and log in.</td></tr></tbody></table>

2. **Navigate to Syslog integration settings**

<table data-header-hidden><thead><tr><th width="76.58203125"></th><th></th></tr></thead><tbody><tr><td><strong>1.</strong></td><td>From the main menu, go to <strong>Orchestrate</strong>→ <strong>SIEM Integrations</strong>.</td></tr><tr><td><strong>2.</strong></td><td>Click <strong>Add Integration</strong>, and select <strong>Syslog</strong>from the drop-down menu</td></tr></tbody></table>

![](/files/86a95c0242e6c31bcb427de246811bde0105b26b)

3. **Edit the Syslog Details window**

<table data-header-hidden><thead><tr><th width="77.77734375"></th><th></th></tr></thead><tbody><tr><td><strong>1.</strong></td><td><strong>Name</strong>: Enter a name for the Syslog SIEM integration.</td></tr><tr><td><strong>2.</strong></td><td><strong>Enabled</strong>: Select to enable SIEM integration.</td></tr><tr><td><strong>3.</strong></td><td><strong>Service Connector</strong>: Select a Service Connector from the drop-down menu:</td></tr><tr><td><strong>4.</strong></td><td><strong>Type of logs</strong>: Select an option from the drop-down menu:<strong>Events:</strong> Send events to Syslog.<strong>Audit Logs:</strong> Send audit logs to Syslog.</td></tr></tbody></table>

4. **Enter Syslog Server Details**

<table data-header-hidden><thead><tr><th width="78.74609375"></th><th></th></tr></thead><tbody><tr><td><strong>1.</strong></td><td><strong>Host:</strong> Enter the BluSapphire DataStreamer’s static private IP.</td></tr><tr><td><strong>2.</strong></td><td><strong>Port Number:</strong> Enter the UDP listener port shared by BluSapphire team.</td></tr><tr><td><strong>3.</strong></td><td>**Transport:**Select TCP</td></tr><tr><td><strong>4.</strong></td><td>Let the other settings remain as default and click <strong>Save</strong>. The Syslog server integration will then be added successfully.</td></tr></tbody></table>

*To test the Syslog server integration, access a decoy and generate alerts on the Zscaler Deception dashboard.*

**Troubleshooting**

| **Symptom**                       | **Likely Cause**                                | **Fix**                                                              |
| --------------------------------- | ----------------------------------------------- | -------------------------------------------------------------------- |
| No logs arriving at syslog server | UDP/TCP blocked by intermediate firewall or ACL | Allow traffic on chosen port from the NetXGATE IP to Datastreamer IP |
