IBM QRadar

IBM QRadar

Join this online topic group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.


#Security
#QRadar
#SecuringhybridcloudandAI
 View Only
  • 1.  ZScaler v6.0 DSM Specifications

    Posted 10/13/21 09:54 AM

    Hi,

    the current DSM Guide describes the specifications for the Zscaler DSM for recorded event types "weblog events and firewall events". What about event type NSS-FW-DNS?

    Those Events are currently stored events. Any plans to include them and update the standard DSM for Zscaler?

    Regards,

    Ralph



    #QRadar
    #Support
    #SupportMigration


  • 2.  RE: ZScaler v6.0 DSM Specifications
    Best Answer

    Posted 10/13/21 02:19 PM

    Ralph,

    This is a topic that likely requires a feature request. Normally, we support certain event types, such as WebApp/Firewall and it would be expected that any other types would need a custom log source type in the DSM Editor.

    If you have a new data or event type that you feel should be included, you probably need to get these opened in the Ideas portal. The Request For Enhancements site was just updated and rebranded to the IBM Security Ideas portal. I would make a QRadar integration request to officially support NSS-FW-DNS events. For more info and direct links, check out: https://ibm.biz/qradarrfefaq.

    New event types require evaluation, so these are typically handled as features (RFEs) or Ideas. The dev teams and product managers review these requests and scope the work required. As these changes might require new parsing formats, large changes to QID maps, potential custom property updates, rule updates, etc.

    I looked at the integrations section of the ideas portal https://ibm.biz/integrationrfe and didn't see anything logged. I would make a request for this event type.



    #QRadar
    #Support
    #SupportMigration


  • 3.  RE: ZScaler v6.0 DSM Specifications
    Best Answer

    Posted 10/13/21 02:41 PM

    Jonathan,

    thank you for this quick response :)

    Will you take care of the request or should I do that?

    Regards,

    Ralph



    #QRadar
    #Support
    #SupportMigration


  • 4.  RE: ZScaler v6.0 DSM Specifications
    Best Answer

    Posted 10/14/21 02:04 AM

    Ralph,

     

    Actually, hold off on opening an Idea/RFE. I talked to the dev team about your request today and apparently, they have been prepping a change for DNS events in ZScaler. There is a QID map change in the 13 October 2021 weekly auto update that contains a QID map update for ZScaler DNS events. However, I didn't see a docs task to update the DSM Guide to list these as supported. As the events are LEEF, you should review your ZScaler events to confirm if they parse. These events should have a category of cat=nss-dns in their payloads.

     

    This change is part of the QID update this week and the changes are in the file ZscalerNss 1633613796010.qidmap-import.xml.

     

    Take a look and let me know if this QID map update fixed the unknowns or if you are seeing other issues and I can inquire further. I checked out QRadar 101 recent updates page and the QID map tab lists ZScaler NSS too. I didn't notice it until I reviewed our automation for the pages updates: https://www.ibm.com/community/qradar/recent/#tab2



    #QRadar
    #Support
    #SupportMigration


  • 5.  RE: ZScaler v6.0 DSM Specifications
    Best Answer

    Posted 10/14/21 01:41 PM

    Hi Jonathan,


    i checked today the qidmap updates. And yes, i found this entry in the view log section of the autoupdate panel: Qidmap delta to be applied 1633613796010 the date you mentioned.

    The Events of Zscaler are LEEF, but the events are not parsed and categorized as 'stored' and the event name is: "Zscaler Nanolog Streaming Service Message".

    The payload looks like:

    Oct 14 15:19:31 zscaler-nss: LEEF:1.0|Zscaler|NSS-FW-DNS|6.0|Allow|tuser= ..... but there is no cat=nss-dns entry available...


    Regards,

    Ralph



    #QRadar
    #Support
    #SupportMigration


  • 6.  RE: ZScaler v6.0 DSM Specifications
    Best Answer

    Posted 10/14/21 03:46 PM

    Hey Ralph,


    I think the issue here is that your product field is incorrect, causing an issue in the expected parsing. I looked at the LEEF events ZScaler dev provided to us and your LEEF payload looks different.


    • Your example: Oct 14 15:19: 31 zscaler-nss: LEEF:1.0|Zscaler|NSS-FW-DNS|6.0|Allow|tuser=


    • Vendor example: Oct 10 15:19:31 zscaler-nss:LEEF:1.0|Zscaler|NSS-FW|6.0|


    I think if you just need to update your LEEF string in your ZScaler configuration to define the product as NSS-FW at the source . After this update, I would expect the events will parse based on what I can see in your example payload.



    #QRadar
    #Support
    #SupportMigration


  • 7.  RE: ZScaler v6.0 DSM Specifications
    Best Answer

    Posted 10/15/21 08:42 AM

    Hi Jonathan,

    as an additional info about my log sample snipet yesterday out of our test environment: this seems to be a new zscaler feed option available to enable nss-fw-dns events. these events would also be of interest in terms of normalizing events. Currently in dsm documentation two feeds options for zscaler are available: firewall and web. In production the zscaler events works as expected with firewall and web feeds - snipet:

    Oct 15 09:52:11 zscaler-nss: LEEF:1.0|Zscaler|NSS|4.1|....


    Just to clarify my question :)


    The LEEF String Zscaler NSS-FW-DNS comes from this additonal Zscaler Feed.

    But more of a feature request?


    Regards,

    Ralph



    #QRadar
    #Support
    #SupportMigration