T Techclick ← All lessons
Zscaler · Batch 11 · Lesson 13 · Logs + ZDX

Logs + ZDX — which log answers which ticket

Friday 17:04. Sales Slack: “Salesforce is broken for APAC.” CIO is already in the channel. The wrong first click wastes an hour in Web Insights while the hop that actually died sits in ZDX. This lesson is the four surfaces — Web Insights, Nanolog / NSS, ZPA diagnostics, ZDX hop path — mapped to five production tickets, each with a first tool and a proof field.

~20 min read · L2 primary · Quiz at end

⚡ Quick Answer

Which Zscaler log closes which ticket: Web Insights vs Nanolog vs ZPA diagnostics vs ZDX hop path. Five production tickets with first tool and proof field.

After this page you can

Quick answer (say this out loud)

Web Insights answers “was this internet/SaaS transaction allowed, blocked, or cautioned, and which policy?” — Policy Action + Blocked Policy Name. Nanolog is the cloud store those rows come from; NSS streams the same fields to your SIEM when Insights retention is not enough. ZPA Diagnostics → User Activity answers “did this user reach this private app?” — Connection Status, Policy, Connector. ZDX Cloud Path → Hop View answers “where on the path did it get slow?” — hop latency and packet loss. An Allow in Insights is not a healthy path.

1. Why four surfaces exist

A block page, a spinner, a slow SaaS tab, and “it worked last quarter” look the same in Slack. They are four different questions. Zscaler ships four surfaces so you do not answer a latency ticket with a URL rule change.

Web Insights is the in-tenant transaction log for internet and SaaS that went through ZIA. Nanolog is the backend those logs live in; Insights is the GUI over it, and NSS is the pipe out of it. ZPA diagnostics is not a web log — it is the private-app session decision. ZDX is not a policy engine — it measures the hop path the user felt.

Hero · four tiles, one user
User and laptop connected through a cloud broker to a SaaS building, with four abstract telemetry tiles on a wall monitor
Notice: one user session, four questions. Logs = policy. SIEM = history. Private-access path = ZPA. Hop line = ZDX.
Interview line

If they say “check the logs,” name the surface. “I opened Insights” is incomplete. Say: “If Policy Action is Allowed and the user still says slow, I leave policy alone and open ZDX Cloud Path Hop View.”

2. Mental model — Insights, Nanolog, Diagnostics, ZDX

Memorise four named objects before you open any Admin Portal. Every ticket in this lesson maps back to one of them.

Web Insights Logs

ZIA Admin → Analytics → Insights Logs → Web (Help title: Web Insights Logs). Live GUI over Nanolog. Columns that close tickets: Policy Action, Blocked Policy Name, URL Category, Cloud Application.

Nanolog + NSS

Nanolog is the Zscaler cloud log cluster. Nanolog Streaming Service (NSS) (Administration → Nanolog Streaming Service) streams those records to Splunk / Sentinel / QRadar / Elastic. Use it when Insights retention is too short or you must join Zscaler with EDR.

ZPA User Activity diagnostics

ZPA Admin → Logs → Insights → Diagnostics, Log Type = User Activity. This is the private-app session, not a URL. Proof: Connection Status, Application Segment, Policy, Connector.

ZDX Cloud Path / Hop View

ZDX Admin → Users (or Applications) → Cloud Path. Hop View and Command Line View show per-hop latency and packet loss. A ZDX Score is 0–100 (higher is better). The score drop is the alert; the hop is the proof.

Flow 1 · four questions, four stores
One session · four stores · pick by the question User + destination + time write these on the ticket first Web Insights Allowed / Blocked / Caution Policy Action Blocked Policy Name in-tenant · SKU retention Nanolog → NSS same fields, your SIEM 12–24 month hunt join EDR / mail / IdP not a live GUI trace ZPA Diagnostics User Activity Connection Status Policy · Connector private app only ZDX Hop View Cloud Path probe latency · packet loss ZDX Score 0–100 not a policy verdict Insights queries Nanolog. NSS copies Nanolog. Neither one draws hops. ZDX draws hops. ZPA Diagnostics names the Connector. Do not swap them.

Read left → right. Insights and NSS share a store. ZPA and ZDX are different questions, even when the user used the same Client Connector.

3. Decision flow — ticket → first tool

Flowchart first. Do not open policy until the diamond says so.

Flow 2 · first-tool diamond
Symptom first · tool second · field third What failed? Public / SaaS or private app? Blocked / caution Web Insights Policy Action Allowed but slow ZDX Hop View latency · loss Private FQDN ZPA User Activity Connection Status Older than Insights Nanolog → NSS SIEM field search No ZIA rows at all? → Tunnel Insights first Client Tunnel IP · Client Connector Tunnel Version · then PAC / 443 egress Diamond = decision. Do not edit a URL rule from the bottom box.

Read the diamond first. Private FQDN never starts in Web Insights. Allowed + slow never starts in policy. Empty Web log starts in Tunnel Insights.

Path · one red hop is the ticket
Laptop to SaaS hop path with healthy cyan nodes and one cracked red hop labelled Edge
Notice: Insights can still say Allowed while the hop between Edge and SaaS is the failure. That is a ZDX ticket, not a URL ticket.

4. How to choose — field-level map

If you can recite this table, the rest of the lesson is practice.

If the ticket says…First tool (official path)Proof fieldDo not open first
Site / SaaS blocked or caution EUN after a policy changeZIA Analytics → Insights Logs → WebPolicy Action (Allowed / Blocked / Caution) + Blocked Policy NameZDX Score, ZPA Diagnostics
SaaS is slow; Insights already shows AllowedZDX Users / Applications → Cloud Path → Hop ViewPer-hop latency and packet loss; ZDX Score vs that user’s baselineA new URL Block
jira.corp.internal / any private FQDN “no connection”ZPA Logs → Insights → Diagnostics · Log Type User ActivityConnection Status + Policy + Connector (+ Application Segment)Web Insights URL Category
Auditor: 12 months of DLP / web by userAdministration → Nanolog Streaming Service → SIEM searchNSS Web feed fields streamed from Nanolog (user / login, action, DLP engine / rule labels)Insights GUI (retention ages out)
Client Connector red, whole site, no Web rowsZIA Analytics → Insights Logs → TunnelClient Tunnel IP, Zscaler Client Connector Tunnel Version, up/down timeA Cloud App rule edit
Hard words, once

Nanolog is the store. Insights Logs is the GUI that queries it. NSS is the streamer out of it. LSS is the ZPA-side log streamer (Log Streaming Service) — do not call ZPA’s feed “NSS.” Cloud Path is the ZDX probe that walks hops. Hop View is the visualisation of that probe (Help also documents a Command Line View).

5. Runbook Side A → B → C

Side A is the ZIA live log. Side B is the ZPA session. Side C is experience + long-term store. Do them in this order on a messy Sev-2 when you do not yet know the layer.

Side A — ZIA Insights Logs (live policy proof)

  1. Open Web Insights, not the policy editor

    Path: Analytics → Insights Logs → Web. Official page title is Web Insights Logs. Filter User + time window that covers the ticket. Add URL or Cloud Application if you already know the destination.

  2. Read the three columns that close a policy ticket

    Policy Action — Allowed, Blocked, or Cautioned. Blocked Policy Name — which policy took the action. URL Category and Cloud Application (plus Cloud Application Class) — what the engine thought it saw. Source: Web Insights Logs: Columns.

  3. If there are zero Web rows, switch type — do not invent a URL rule

    Same Insights Logs page has sibling types documented from About Insights Logs: Firewall, DNS, Tunnel, Mobile, and others. Site-wide Client Connector red belongs in Tunnel Insights Logs (Client Tunnel IP, Zscaler Client Connector Tunnel Version).

admin.zscaler.net · Analytics → Insights Logs → Web
Training mock · not live

Analytics / Insights Logs / Web

Web Insights Logs

priya@lab.example
Last 15 minutes
Microsoft Exchange Online
Blocked
UserURL / AppURL CategoryPolicy ActionBlocked Policy Name
priya@lab.exampleoutlook.office.comWebmailAllowed
priya@lab.exampleattachment.outlook.office.comWebmailBlockedDLP-PII-OWA-Attach

Source: Zscaler Help — About Insights Logs; Web Insights Logs: Columns (Policy Action, Blocked Policy Name, URL Category, Cloud Application). Lab identities only.

Side B — ZPA Diagnostics (private-app session)

  1. Open User Activity, not Web Insights

    Path: Logs → Insights → Diagnostics. From Log Type, select User Activity. Official article: Accessing User Activity Diagnostics. Filter Username + Application Segment + time.

  2. Read Connection Status, then Policy, then Connector

    Help documents Connection: Status as a filter on this page. Session status codes live on Understanding Private Access Session Status Codes. LSS User Activity fields (same session, streamed) include ConnectionStatus, Policy, Connector, Application, AppGroup, Server, InternalReason.

  3. If there is no User Activity row, check User Status

    Same Diagnostics page, Log Type = User Status. That answers “did Client Connector even attach to a ZPA Service Edge?” — not “did Jira load.” Posture misses show on the user-status side (LSS: PosturesMiss).

ZPA User Activity — fields you write in the ticket (LSS names)
Log Type:        User Activity
Username:        contractor@lab.example
Application:     Jira-Prod
ConnectionStatus + Policy + Connector + Server
InternalReason   ← why the broker refused, if it refused

Side C — ZDX hop path + Nanolog/NSS

  1. Confirm the app is actually probed

    ZDX does not invent data for every SaaS. If Workday has no probe, the Users dashboard will not grow a Cloud Path. Inventory the top user-facing apps and attach Web / Cloud Path probes (Help: Configuring Zscaler Managed Probes — includes a Hop Count setting).

  2. Open Cloud Path → Hop View

    Official: Evaluating the Cloud Path. ZDX traces the end-to-end path and measures latency and packet loss between hops. Hop View and Command Line View both exist; errors also appear as icons (Cloud Path Errors). The bad hop is the proof field — not the headline ZDX Score.

  3. If the question is “show me last year,” leave the GUI

    Path: Administration → Nanolog Streaming Service → NSS Feed (Web, Firewall, DNS, Tunnel, and the rest). Official: Understanding Nanolog Streaming Service; NSS Feed Output Format: Web Logs. Insights is still querying Nanolog — it just will not keep the row as long as your SIEM will.

admin.zdxcloud.net · Users → priya@lab.example → Applications → Salesforce → Cloud Path
Training mock · not live

Users / priya@lab.example / Salesforce / Cloud Path

Cloud Path · Hop View

41 ↓ from 92 (7-day baseline)
Cloud Path · Salesforce
Hop View
Latency + packet loss
HopSegmentLatencyPacket loss
1Endpoint → local gateway4 ms0%
2ISP12 ms0%
3ZIA Public Service Edge18 ms0%
4PSE → Salesforce edge480 ms8%

Source: Zscaler Help — Evaluating the Cloud Path; Cloud Path Errors; Understanding the ZDX Score. Hop numbers are a lab story, not a live tenant. Training mock · not live.

6. Five tickets — first tool + proof

These five land every quarter. Memorise first tool + proof field. The runbook above is how you walk them.

TicketSymptomFirst toolProof field
INC-4812After a new DLP rule, Outlook Web loads but attachments failAnalytics → Insights Logs → WebPolicy Action = Blocked · Blocked Policy Name = the DLP rule
INC-4813Salesforce slow for all of APAC; Insights shows AllowedZDX → Cloud Path → Hop ViewHop with jump in latency / packet loss (often PSE → SaaS, not the laptop)
INC-4814jira.corp.internal — Client Connector “no connection”ZPA Logs → Insights → Diagnostics → User ActivityConnection Status + Policy + Connector
INC-4815Auditor: “All DLP triggers for PII, by user, last 12 months”Nanolog via NSS → SIEMNSS Web log user / action / DLP engine fields over SIEM retention
INC-4816Branch: Client Connector red on every laptop since 02:00; no Web rowsAnalytics → Insights Logs → TunnelClient Tunnel IP + tunnel up/down time; then confirm 443 egress to Zscaler

INC-4812 — OWA attachments, new DLP

Web Insights, not ZPA. Outlook on the Web is internet/SaaS. Filter User + Cloud Application (or URL containing outlook.office.com) + last hour. If the page itself is Allowed and the attachment host is Blocked, Blocked Policy Name is the ticket. Change that one rule — or narrow its DLP engine — Activate, then re-read the same three columns.

INC-4813 — Salesforce slow, Insights Allowed

Do not add a URL Allow. Policy already allowed it. Open ZDX for Salesforce, APAC users, Cloud Path. If hops 1–3 (endpoint → ISP → Public Service Edge) are baseline and hop 4 (edge → Salesforce) spikes, that is a path/peering problem. Check Zscaler Trust / status, then a temporary forwarding change only if your runbook already has a known-good failover. Close with the hop row, not a policy screenshot.

INC-4814 — Jira via ZPA

Web Insights will not show jira.corp.internal as a URL category hit. User Activity tells you whether Access Policy matched, which Connector was chosen, and whether Connection Status failed. If there is no User Activity row, User Status tells you the device never built a ZPA session (token, posture, or Client Connector). After you edit a policy, re-query User Activity — Activate is not proof.

INC-4815 — Twelve-month DLP

Insights retention is SKU-dependent and ages out. That is why NSS exists. Administration → Nanolog Streaming Service → a Web NSS feed into the SIEM, with parsers actually installed. If the feed is up but no CIM / content pack is mapped, you have raw syslog and no audit answer. Do not promise Insights will cover a year.

INC-4816 — Site-wide tunnel red

Zero Web rows is data. Open Tunnel Insights for that location and time. Simultaneous failure at 02:00 after a firewall change is almost never “everyone’s SAML token expired together” — tokens stagger. Confirm outbound 443 to Zscaler Public Service Edges, then Client Connector version. PAC-only users with a broken PAC return DIRECT and also vanish from Insights; tunneled Client Connector users would still appear. That split is the PAC tell.

Green success on each ticket

7. Traps + close-the-ticket proof

Proof · named field, then Closed
Operations desk with blurred green health checks on one monitor and a hop path with one amber node on the other
Notice: the close is a named column on a timestamp, not a screenshot of the user’s Salesforce tab.
TrapWhat it looks likeFirst check
Treating Allowed as healthyUser says slow; you keep editing URL rulesPolicy Action = Allowed → leave policy. ZDX Hop View.
Web Insights for a private FQDNEmpty Web log, Jira still deadZPA Diagnostics · User Activity.
ZDX deployed, no probe for that appScore pane says no data while Slack burnsConfiguration → probes. Workday / custom apps are opt-in.
Trusting ZDX Score without Hop ViewScore is low; you blame ZIAScore is a rollup. The hop (or device CPU / Wi-Fi) is the cause.
Calling ZPA’s stream “NSS”SIEM has ZIA Web and nothing for ZPAZIA = NSS. ZPA = LSS (Log Streaming Service).
NSS ingest, no parsersAuditor ask fails even though EPS is healthyInstall the vendor content pack; search the official Web feed fields.
Tunnel-down hunted in WebNo rows, you assume “policy dropped everything”Tunnel Insights. Then 443 egress / PAC / trusted-network disable.
Activate without a re-queryZPA policy “fixed,” user still blockedRe-run User Activity. A higher-priority Policy or PosturesMiss may still win.
Pilot checklist (weekly, not after the Sev-2)
Say this out loud

Insights tells me the verdict. Nanolog plus NSS keeps the verdict. ZPA Diagnostics names the Connector. ZDX names the hop. I do not change a URL rule because a hop died.

Knowledge check

Six judgment items. Each one maps to a ticket or a trap. Check answers, then Reset if you picked the wrong surface.

Q1

APAC reports Salesforce is slow. Web Insights Policy Action is Allowed. Which first tool answers where the path died?

Correct: c. Allowed means policy is not the layer. Hop View is the official Cloud Path visualisation of latency and loss. Re-read §3 and INC-4813.
Q2

A new DLP rule shipped an hour ago. Outlook Web opens; attachments fail. Which proof field closes INC-4812?

Correct: a. Official Web Insights columns. ZPA is private apps. ZDX is experience. Tunnel is “is the client even up.” Re-read Side A and INC-4812.
Q3

The auditor wants every DLP trigger for PII, by user, for the last 12 months, joined with EDR. What is the right store?

Correct: b. Insights queries Nanolog but retention ages out (SKU-dependent). NSS is the official streamer for long SIEM retention and joins. Re-read Side C and INC-4815.
Q4

A contractor cannot reach jira.corp.internal. Client Connector says no connection. First tool + proof?

Correct: b. Official path and User Activity fields. Web Insights is ZIA internet/SaaS. ZDX hop path does not replace a policy/Connector decision. Re-read Side B and INC-4814.
Q5

Web Insights Policy Action is Allowed. The user still says “Zscaler is slow.” What do you do first?

Correct: d. Allowed is not a healthy path. Changing URL policy adds risk and cannot name a hop. Re-read the diamond in §3 and the first trap in §7.
Q6

A branch reports Client Connector red on every laptop since a 02:00 firewall change. Web Insights is empty. Which Insights type first?

Correct: b. Empty Web is the clue the tunnel never landed. Tunnel Insights is a documented Insights Logs type. Simultaneous 02:00 failure points at egress, not staggered auth. Re-read Side A step 3 and INC-4816.

Sources

Related: Lesson 12 · Isolation + SIPA · Lesson 5 · URL + Cloud App (Web Insights proof) · Lesson 9 · ZPA architecture · Lesson 10 · ZPA Connectors · Lesson 14 · ZDTA + interview · Authentication (identity before logs)