Adding a MaaS360 threat connector in the IBM MaaS360 Portal
Create a MaaS360® threat connector in the IBM® MaaS360 Portal to receive logs from the Zscaler cloud. The MaaS360 threat connector uploads events that are received from the Zscaler NSS service to a threat relay. The threat relay processes the events before the event is sent to the IBM MaaS360 Portal.
Adding a threat connector in the IBM MaaS360 Portal
- Select .
- Click Add Connector.
- Enter the following settings for the name and description of the threat connector.
- Enter a unique name and description for the threat connector.
- Select Zscaler as the threat vendor.
- Click Validate Details, and then click Next.
- Configure relay and installation settings for the threat connector.
- Select the threat relay that processes threat information. Use the relay that is closest to the location where the MaaS360 threat connector is installed.
- Select the installation mode for the threat connector.
- StandAlone: Standalone mode allows installation of the threat connector only.
- HA: High availability mode allows multiple installations of a threat connector. For this mode, you must set up a load balancer and configure the load balancer to split traffic between multiple connector nodes.
Note: You need the IP address of the host name to configure Zscaler NSS feeds in the Zscaler portal. For more information about Zscaler NSS feeds, see Setting up the Zscaler Nanolog Streaming Service (NSS) virtual machine and Configuring the Zscaler NSS feed from the Zscaler admin portal. - Save your changes and click Next.
- Download the threat connector and the certificate, and then save the certificate password.
The threat connector is displayed in the threat connector list view in the IBM MaaS360 Portal. The administrator can edit or modify threat connectors by selecting the threat connector and clicking the Edit action.
- On the Threat Connectors page, click the vertical dots menu and select Downloads to download the threat connector and its certificate.