Skip to content

kinneygroup/itsi-zscaler

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commit
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Summary

The ITSI Content Pack for Zscaler from Kinney Group is specifically designed to monitor system health related to Zscaler services. It leverages Splunk ITSI to provide in-depth analysis and visualization of logs for Zscaler, ensuring critical systems are operating optimally. This content pack is an essential tool for IT professionals looking to enhance the reliability and performance of their infrastructure.

  • Comprehensive Performance Monitoring: Offers detailed insights into Zscaler service performance, including application, network, and user experience metrics, enabling optimized resource utilization.
  • Critical System Status Tracking: Monitors the real-time operational status of Zscaler services, helping IT professionals swiftly identify and address potential issues.
  • Enhanced User Experience: Facilitates better decision-making on resource allocation and system adjustments by analyzing performance trends and detecting inefficiencies across the infrastructure.

Kinney Group ITSI Content Pack Blog

This ITSI Content Pack is open source and available for community collaboration and enhancement on GitHub.

For more information about Kinney Group's Splunk Products, visit our website

Details

The ITSI Content Pack for Zscaler contains service definitions and KPIs ready to import to ITSI. The KPI Thresholds and importance values are set to defaults so that they can be tuned manually for your use case. After configuration, this content pack provides a comprehensive view of Zscaler service performance, helping to ensure optimal digital experiences.

Kinney Group ITSI Content Pack Blog

For more information about Kinney Group's Splunk Products, visit our website

Services

Zscaler monitoring encompasses several specialized services, each targeting specific aspects of performance:

  1. Zscaler Digital Experience
  2. Application Performance
  3. Network Performance
  4. User Experience
  5. Database Performance
    • Description: Monitors database query performance, connection counts, and other relevant metrics to ensure database health.
    • Source: Zscaler and Splunk Solution Brief
  6. Service Response Times
    • Description: Measures the response times of critical services and APIs to ensure they are performing within acceptable thresholds.
    • Source: Zscaler and Splunk Deployment Guide
  7. Network Traffic
  8. Service Dependencies
    • Description: Maps and monitors dependencies between services to understand the impact of one service's health on another.
    • Source: Zscaler and Splunk Solution Brief
  9. Security Events
  10. Log Analysis

KPIs

Each service utilizes specific KPIs to measure its effectiveness:

  1. System Availability
  2. Response Times
  3. Application Load Time
  4. Application Error Rate
  5. Network Latency
  6. Packet Loss
  7. Bandwidth Utilization
  8. Response Time
  9. Transaction Time
  10. User Session Metrics
  11. Unauthorized Access Attempts
  12. Database Query Response Time
  13. Database Connection Count
  14. Database Error Rate
  15. API Response Time
  16. Service Uptime
  17. Service Error Rate
  18. Inbound Traffic Volume
  19. Outbound Traffic Volume
  20. Dependency Health
  21. Malware Detections
  22. Security Incident Logs
  23. Log Collection Rate

Relationships

Dependencies:

Services are interconnected; for instance, Zscaler Digital Experience is dependent on Application Performance, Network Performance, and User Experience services. Similarly, Application Performance relies on Database Performance and Service Response Times.

Hierarchical Structure:

Some services form a hierarchy, such as Network Performance depending on Network Traffic, illustrating a layered approach to performance monitoring where base metrics support broader performance indicators.

Installation

Installation prerequisites:

Splunk Addon for Zscaler

Splunk App for Content Packs

Splunk ITSI

Troubleshooting

Kinney Group ITSI Content Pack Blog

Github and Readme

support@kinneygroup.com

Contact

To provide feedback, visit our Github and Readme for our content packs.

support@kinneygroup.com

For more information about Kinney Group's Splunk Products, visit our website

Version History

Version Date Description
0.0.1 06/06/2024 Initial Preview Release

Considerations:

Kinney Group ITSI Content Pack Blog

Releases

No releases published

Packages

No packages published