Set up
- Follow the shared Log Forwarders guide to add Zscaler ZPA (Syslog) and open Forwarder Details
- Login to the ZPA Admin Portal
- Navigate to Configuration & Control > Private Infrastructure > Log Streaming Service > Log Receivers
- Click Add Log Receiver and configure the Log Receiver tab:
- Name: A descriptive name (e.g., “Wirespeed”)
- Domain or IP Address: Hostname or IP from Forwarder Details
- TCP Port: Listener port from Forwarder Details
- App Connector Groups: Select the groups whose logs you want to forward
- Click Next and configure the Log Stream tab:
- Log Type: Select the desired log type (e.g., User Activity, Browser Access)
- Log Template: Select JSON
- Log Stream Content: Use the default template
- Click Save
ZPA logs should reflect shortly underneath the Events page.
Zscaler ZPA sends logs via App Connectors, not directly from the ZPA cloud. Ensure the selected App Connector Groups have network connectivity to the Wirespeed hostname and port.