HTTP Receiver log source parameters for Zscaler NSS

If IBM® QRadar® does not automatically detect the log source, add a Zscaler NSS log source on the QRadar Console by using the HTTP Receiver protocol.

When you use the HTTP Receiver protocol, there are specific parameters that you must use.

The following table describes the parameters that require specific values to collect HTTP Receiver events from Zscaler NSS:
Table 1. HTTP Receiver log source parameters for the Zscaler NSS DSM

Parameter

Description

Log Source type Zscaler NSS
Protocol Configuration HTTP Receiver
Log Source Identifier

Type the IP address as an identifier for events from your Zscaler NSS installation.

The log source identifier must be a unique value.

Important: When you use the HTTP protocol, you must use a certificate that is issued by a certificate authority (CA). It can't be a self-signed certificate because it must be validated by a CA. For more information about certificates and configuring the log source parameters for HTTP receiver, see HTTP Receiver protocol configuration options.