---
title: Zscaler ZIA & ZPA Integrations
description: The AgileBlue SOC | XDR platform provides automated data collection and configuration services for your Zscaler environment. This integration can be used to receive logs sent by NSS log server on the
---

[Skip to content](https://help.agileblue.com/zscaler-zia-zpa-integrations#main-content)

English

Show submenu for translations

[Contact AgileBlue Support](https://help.agileblue.com/kb-tickets/new?hsLang=en) [Customer portal](https://help.agileblue.com/support-ticket-status?hsLang=en)

![FullColor-800px-Aug-04-2025-07-56-16-5066-PM.png\]](https://help.agileblue.com/hs-fs/hubfs/FullColor-800px-Aug-04-2025-07-56-16-5066-PM.png?height=32&name=FullColor-800px-Aug-04-2025-07-56-16-5066-PM.png)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [Contact AgileBlue Support](https://help.agileblue.com/kb-tickets/new)
- [Customer portal](https://help.agileblue.com/support-ticket-status)
- AgileBlue Portal

 AgileBlue Portal

 Hello. How can we help you?

- There are no suggestions because the search field is empty.

1. [Help Center](https://help.agileblue.com/?hsLang=en)
2. [Application Integrations](https://help.agileblue.com/application-integrations?hsLang=en)
3. [Other Security Tools](https://help.agileblue.com/application-integrations?hsLang=en#other-security-tools)

# Zscaler ZIA & ZPA Integrations

### **OVERVIEW**

The AgileBlue SOC | XDR platform provides automated data collection and configuration services for your Zscaler environment. This integration can be used to receive logs sent by NSS log server on the specified TCP port, or by LSS Log Receiver on respective TCP ports. 

### **Supported Zscaler Integrations**

- Zscaler Internet Access (ZIA)
- Zscaler Private Access (ZPA)

### **Setup Notes**

- A syslog server must be registered to your AgileBlue Syslog Policy in order to access this integration. Please [click here](https://help.agileblue.com/installing-agileblues-agent-on-a-syslog-server?hsLang=en) for additional information.
- Before proceeding with the steps below, please contact AgileBlue Support to configure the Zscaler integration on your Syslog Policy.

---

### **Setup Steps - ZIA**

1. Log in to the **ZIA Admin Portal** using your admin account.
2. Add an **NSS server**. [Click here](https://help.zscaler.com/zia/adding-nss-servers) for reference. 
     1. Verify the NSS Server is healthy by accessing **Administration \> Nanolog Streaming Service \> NSS Servers**
3. Add the NSS Feeds you would like to configure. [Click here](https://help.zscaler.com/zia/adding-nss-feeds) for reference.
4. Configure the **Zscaler NSS Server** and **NSS Feeds** to send logs to your Syslog Server registered with AgileBlue on the specified port. 
     1. ZIA Alerts: 9010 TCP
     2. ZIA DNS Logs: 9011 TCP
     3. ZIA Firewall Logs: 9012 TCP
     4. ZIA Tunnel Logs: 9013 TCP
     5. ZIA Web Logs: 9014 TCP
5. Once this is complete, contact AgileBlue Support to confirm the data stream.

---

### **Setup Steps - ZPA**

1. Configure the **Zscaler LSS Log Receiver** to send logs to your Syslog Server registered with AgileBlue. 
     1. Reference [this guide](https://help.zscaler.com/zpa/configuring-log-receiver) for help setting up a log receiver.
     2. Reference [this guide](https://help.zscaler.com/zpa/configuring-log-receiver) for help configuring the log receiver.
2. Specify the **TCP input** based on the following log types: 
     1. ZPA App Connector Status Logs: 9015 TCP
     2. ZPA Audit Logs: 9016 TCP
     3. ZPA Browser Access Logs: 9017 TCP
     4. ZPA User Activity Logs: 9018 TCP
     5. ZPA User Status Logs: 9019 TCP
3. Once this is complete, contact AgileBlue Support to confirm the data stream.

---

**Need Help?**

AgileBlue is always here to support you and ensure you are 100% successful. If there are any issues with the installation or if you have any questions, please reach out to [**AgileBlue Support**](https://help.agileblue.com/kb-tickets/new?hsLang=en).

*Email: support@agileblue.com   
Phone: (216) 606-9400🚨*

- [Agent Installation](https://help.agileblue.com/agent-installation?hsLang=en#main-content)

    - [Windows](https://help.agileblue.com/agent-installation?hsLang=en#windows)
    - [Mac](https://help.agileblue.com/agent-installation?hsLang=en#mac)
    - [Linux](https://help.agileblue.com/agent-installation?hsLang=en#linux)
    - [Syslog Collection](https://help.agileblue.com/agent-installation?hsLang=en#syslog-collection)
    - [Agent Management](https://help.agileblue.com/agent-installation?hsLang=en#agent-management)
- [Application Integrations](https://help.agileblue.com/application-integrations?hsLang=en#main-content)

    - [Microsoft Tools](https://help.agileblue.com/application-integrations?hsLang=en#microsoft-tools)
    - [Third-Party EDR](https://help.agileblue.com/application-integrations?hsLang=en#third-party-edr)
    - [Other Security Tools](https://help.agileblue.com/application-integrations?hsLang=en#other-security-tools)
- [Cloud Integrations](https://help.agileblue.com/cloud-integrations?hsLang=en)
- [AgileBlue Features](https://help.agileblue.com/agileblue-features?hsLang=en#main-content)

    - [Portal Management](https://help.agileblue.com/agileblue-features?hsLang=en#portal-management)
    - [Support Systems](https://help.agileblue.com/agileblue-features?hsLang=en#support-systems)
- [Vulnerability Scanning](https://help.agileblue.com/vulnerability-scanning?hsLang=en)
- [Release Notes](https://help.agileblue.com/release-notes?hsLang=en)

[![AgileBlue](https://help.agileblue.com/hs-fs/hubfs/Current-Website-Logo-Replacement.png?width=1321&height=648&name=Current-Website-Logo-Replacement.png "AgileBlue")](http://www.agileblue.com)

AgileBlue Support Phone: 216.606.9400

Copyright © 2026, AgileBlue