# Logs + ZDX — which log answers which ticket

Source: https://ai.techclick.in/blog_zscaler_b11_13_logs_zdx_troubleshooting
Markdown: https://ai.techclick.in/blog_zscaler_b11_13_logs_zdx_troubleshooting.md
Publisher: Techclick Infosec Pvt Ltd

Which Zscaler log closes which ticket: Web Insights vs Nanolog vs ZPA diagnostics vs ZDX hop path. Five production tickets with first tool and proof field.

Quick answer (say this out loud)

    Web Insights  answers “was this internet/SaaS transaction allowed, blocked, or cautioned, and which policy?” —  Policy Action  +  Blocked Policy Name .  Nanolog  is the cloud store those rows come from;  NSS  streams the same fields to your SIEM when Insights retention is not enough.  ZPA Diagnostics → User Activity  answers “did this user reach this private app?” —  Connection Status ,  Policy ,  Connector .  ZDX Cloud Path → Hop View  answers “where on the path did it get slow?” — hop  latency  and  packet loss . An Allow in Insights is not a healthy path.

## 1. Why four surfaces exist

 A block page, a spinner, a slow SaaS tab, and “it worked last quarter” look the same in Slack. They are four different questions. Zscaler ships four surfaces so you do not answer a latency ticket with a URL rule change.

  Web Insights  is the in-tenant transaction log for internet and SaaS that went through ZIA.  Nanolog  is the backend those logs live in; Insights is the GUI over it, and NSS is the pipe out of it.  ZPA diagnostics  is not a web log — it is the private-app session decision.  ZDX  is not a policy engine — it measures the hop path the user felt.

   Hero · four tiles, one user

   Notice: one user session, four questions. Logs = policy. SIEM = history. Private-access path = ZPA. Hop line = ZDX.

   Interview line

   If they say “check the logs,” name the surface. “I opened Insights” is incomplete. Say: “If Policy Action is Allowed and the user still says slow, I leave policy alone and open ZDX Cloud Path Hop View.”

## 2. Mental model — Insights, Nanolog, Diagnostics, ZDX

 Memorise four named objects before you open any Admin Portal. Every ticket in this lesson maps back to one of them.

#### Web Insights Logs

     ZIA Admin →  Analytics → Insights Logs → Web  (Help title: Web Insights Logs). Live GUI over Nanolog. Columns that close tickets:  Policy Action ,  Blocked Policy Name ,  URL Category ,  Cloud Application .

#### Nanolog + NSS

     Nanolog is the Zscaler cloud log cluster.  Nanolog Streaming Service (NSS)  (Administration → Nanolog Streaming Service) streams those records to Splunk / Sentinel / QRadar / Elastic. Use it when Insights retention is too short or you must join Zscaler with EDR.

#### ZPA User Activity diagnostics

     ZPA Admin →  Logs → Insights → Diagnostics , Log Type =  User Activity . This is the private-app session, not a URL. Proof:  Connection Status , Application Segment,  Policy ,  Connector .

#### ZDX Cloud Path / Hop View

     ZDX Admin → Users (or Applications) → Cloud Path. Hop View and Command Line View show per-hop  latency  and  packet loss . A ZDX Score is 0–100 (higher is better). The score drop is the alert; the hop is the proof.

   Flow 1 · four questions, four stores

       User session splits to Web Insights, Nanolog NSS, ZPA diagnostics, and ZDX hop path

- One session · four stores · pick by the question User + destination + time write these on the ticket first Web Insights Allowed / Blocked / Caution Policy Action Blocked Policy Name in-tenant · SKU retention Nanolog → NSS same fields, your SIEM 12–24 month hunt join EDR / mail / IdP not a live GUI trace ZPA Diagnostics User Activity Connection Status Policy · Connector private app only ZDX Hop View Cloud Path probe latency · packet loss ZDX Score 0–100 not a policy verdict Insights queries Nanolog. NSS copies Nanolog. Neither one draws hops. ZDX draws hops. ZPA Diagnostics names the Connector. Do not swap them. Read left → right. Insights and NSS share a store. ZPA and ZDX are different questions, even when the user used the same Client Connector. ## 3. Decision flow — ticket → first tool Flowchart first. Do not open policy until the diamond says so. Flow 2 · first-tool diamond Decision diamond: blocked, slow, private app, old history, or no tunnel Symptom first · tool second · field third What failed? Public / SaaS or private app? Blocked / caution Web Insights Policy Action Allowed but slow ZDX Hop View latency · loss Private FQDN ZPA User Activity Connection Status Older than Insights Nanolog → NSS SIEM field search No ZIA rows at all? → Tunnel Insights first Client Tunnel IP · Client Connector Tunnel Version · then PAC / 443 egress Diamond = decision. Do not edit a URL rule from the bottom box. Read the diamond first. Private FQDN never starts in Web Insights. Allowed + slow never starts in policy. Empty Web log starts in Tunnel Insights. Path · one red hop is the ticket Notice: Insights can still say Allowed while the hop between Edge and SaaS is the failure. That is a ZDX ticket, not a URL ticket. ## 4. How to choose — field-level map If you can recite this table, the rest of the lesson is practice. If the ticket says… First tool (official path) Proof field Do not open first Site / SaaS blocked or caution EUN after a policy change ZIA Analytics → Insights Logs → Web Policy Action (Allowed / Blocked / Caution) + Blocked Policy Name ZDX Score, ZPA Diagnostics SaaS is slow; Insights already shows Allowed ZDX Users / Applications → Cloud Path → Hop View Per-hop latency and packet loss ; ZDX Score vs that user’s baseline A new URL Block jira.corp.internal / any private FQDN “no connection” ZPA Logs → Insights → Diagnostics · Log Type User Activity Connection Status + Policy + Connector (+ Application Segment) Web Insights URL Category Auditor: 12 months of DLP / web by user Administration → Nanolog Streaming Service → SIEM search NSS Web feed fields streamed from Nanolog (user / login, action, DLP engine / rule labels) Insights GUI (retention ages out) Client Connector red, whole site, no Web rows ZIA Analytics → Insights Logs → Tunnel Client Tunnel IP , Zscaler Client Connector Tunnel Version , up/down time A Cloud App rule edit Hard words, once Nanolog is the store. Insights Logs is the GUI that queries it. NSS is the streamer out of it. LSS is the ZPA-side log streamer (Log Streaming Service) — do not call ZPA’s feed “NSS.” Cloud Path is the ZDX probe that walks hops. Hop View is the visualisation of that probe (Help also documents a Command Line View). ## 5. Runbook Side A → B → C Side A is the ZIA live log. Side B is the ZPA session. Side C is experience + long-term store. Do them in this order on a messy Sev-2 when you do not yet know the layer. ### Side A — ZIA Insights Logs (live policy proof) #### Open Web Insights, not the policy editor Path: Analytics → Insights Logs → Web . Official page title is Web Insights Logs. Filter User + time window that covers the ticket. Add URL or Cloud Application if you already know the destination.

- #### Read the three columns that close a policy ticket Policy Action — Allowed, Blocked, or Cautioned. Blocked Policy Name — which policy took the action. URL Category and Cloud Application (plus Cloud Application Class) — what the engine thought it saw. Source: Web Insights Logs: Columns.

- #### If there are zero Web rows, switch type — do not invent a URL rule Same Insights Logs page has sibling types documented from About Insights Logs: Firewall, DNS, Tunnel, Mobile, and others. Site-wide Client Connector red belongs in Tunnel Insights Logs ( Client Tunnel IP , Zscaler Client Connector Tunnel Version ).

     admin.zscaler.net · Analytics → Insights Logs → Web

     Training mock · not live

       Analytics / Insights Logs / Web

### Web Insights Logs

          User  priya@lab.example

          Time range  Last 15 minutes

          Cloud Application  Microsoft Exchange Online

          Policy Action  Blocked

           User  URL / App  URL Category  Policy Action  Blocked Policy Name

            priya@lab.example  outlook.office.com  Webmail   Allowed   —
            priya@lab.example  attachment.outlook.office.com  Webmail   Blocked   DLP-PII-OWA-Attach

        Reset filters  Apply

    Source:  Zscaler Help — About Insights Logs; Web Insights Logs: Columns ( Policy Action ,  Blocked Policy Name ,  URL Category ,  Cloud Application ). Lab identities only.

### Side B — ZPA Diagnostics (private-app session)

- #### Open User Activity, not Web Insights Path: Logs → Insights → Diagnostics . From Log Type , select User Activity . Official article: Accessing User Activity Diagnostics. Filter Username + Application Segment + time.

- #### Read Connection Status, then Policy, then Connector Help documents Connection: Status as a filter on this page. Session status codes live on Understanding Private Access Session Status Codes. LSS User Activity fields (same session, streamed) include ConnectionStatus , Policy , Connector , Application , AppGroup , Server , InternalReason .

- #### If there is no User Activity row, check User Status Same Diagnostics page, Log Type = User Status . That answers “did Client Connector even attach to a ZPA Service Edge?” — not “did Jira load.” Posture misses show on the user-status side (LSS: PosturesMiss ).

  ZPA User Activity — fields you write in the ticket (LSS names)  Log Type:        User Activity
Username:        contractor@lab.example
Application:     Jira-Prod
ConnectionStatus + Policy + Connector + Server
InternalReason   ← why the broker refused, if it refused

### Side C — ZDX hop path + Nanolog/NSS

- #### Confirm the app is actually probed ZDX does not invent data for every SaaS. If Workday has no probe, the Users dashboard will not grow a Cloud Path. Inventory the top user-facing apps and attach Web / Cloud Path probes (Help: Configuring Zscaler Managed Probes — includes a Hop Count setting).

- #### Open Cloud Path → Hop View Official: Evaluating the Cloud Path. ZDX traces the end-to-end path and measures latency and packet loss between hops. Hop View and Command Line View both exist; errors also appear as icons (Cloud Path Errors). The bad hop is the proof field — not the headline ZDX Score.

- #### If the question is “show me last year,” leave the GUI Path: Administration → Nanolog Streaming Service → NSS Feed (Web, Firewall, DNS, Tunnel, and the rest). Official: Understanding Nanolog Streaming Service; NSS Feed Output Format: Web Logs. Insights is still querying Nanolog — it just will not keep the row as long as your SIEM will.

     admin.zdxcloud.net · Users → priya@lab.example → Applications → Salesforce → Cloud Path

     Training mock · not live

       Users / priya@lab.example / Salesforce / Cloud Path

### Cloud Path · Hop View

          ZDX Score  41 ↓ from 92 (7-day baseline)

          Probe  Cloud Path · Salesforce

          View  Hop View

          Metric  Latency + packet loss

           Hop  Segment  Latency  Packet loss

            1  Endpoint → local gateway  4 ms  0%
            2  ISP  12 ms  0%
            3  ZIA Public Service Edge  18 ms  0%
            4  PSE → Salesforce edge  480 ms  8%

        Command Line View  Refresh probe

    Source:  Zscaler Help — Evaluating the Cloud Path; Cloud Path Errors; Understanding the ZDX Score. Hop numbers are a lab story, not a live tenant. Training mock · not live.

## 6. Five tickets — first tool + proof

 These five land every quarter. Memorise first tool + proof field. The runbook above is how you walk them.

     Ticket  Symptom  First tool  Proof field

       INC-4812   After a new DLP rule, Outlook Web loads but attachments fail  Analytics → Insights Logs → Web   Policy Action  = Blocked ·  Blocked Policy Name  = the DLP rule
       INC-4813   Salesforce slow for all of APAC; Insights shows Allowed  ZDX → Cloud Path → Hop View  Hop with jump in  latency  /  packet loss  (often PSE → SaaS, not the laptop)
       INC-4814    jira.corp.internal  — Client Connector “no connection”  ZPA Logs → Insights → Diagnostics → User Activity   Connection Status  +  Policy  +  Connector
       INC-4815   Auditor: “All DLP triggers for PII, by user, last 12 months”  Nanolog via NSS → SIEM  NSS Web log user / action / DLP engine fields over SIEM retention
       INC-4816   Branch: Client Connector red on every laptop since 02:00; no Web rows  Analytics → Insights Logs → Tunnel   Client Tunnel IP  + tunnel up/down time; then confirm 443 egress to Zscaler

### INC-4812 — OWA attachments, new DLP

 Web Insights, not ZPA. Outlook on the Web is internet/SaaS. Filter User + Cloud Application (or URL containing outlook.office.com) + last hour. If the page itself is Allowed and the attachment host is Blocked,  Blocked Policy Name  is the ticket. Change that one rule — or narrow its DLP engine — Activate, then re-read the same three columns.

### INC-4813 — Salesforce slow, Insights Allowed

 Do not add a URL Allow. Policy already allowed it. Open ZDX for Salesforce, APAC users, Cloud Path. If hops 1–3 (endpoint → ISP → Public Service Edge) are baseline and hop 4 (edge → Salesforce) spikes, that is a path/peering problem. Check Zscaler Trust / status, then a temporary forwarding change only if your runbook already has a known-good failover. Close with the hop row, not a policy screenshot.

### INC-4814 — Jira via ZPA

 Web Insights will not show  jira.corp.internal  as a URL category hit. User Activity tells you whether Access Policy matched, which Connector was chosen, and whether  Connection Status  failed. If there is no User Activity row, User Status tells you the device never built a ZPA session (token, posture, or Client Connector). After you edit a policy, re-query User Activity — Activate is not proof.

### INC-4815 — Twelve-month DLP

 Insights retention is SKU-dependent and ages out. That is why NSS exists. Administration → Nanolog Streaming Service → a Web NSS feed into the SIEM, with parsers actually installed. If the feed is up but no CIM / content pack is mapped, you have raw syslog and no audit answer. Do not promise Insights will cover a year.

### INC-4816 — Site-wide tunnel red

 Zero Web rows is data. Open Tunnel Insights for that location and time. Simultaneous failure at 02:00 after a firewall change is almost never “everyone’s SAML token expired together” — tokens stagger. Confirm outbound 443 to Zscaler Public Service Edges, then Client Connector version. PAC-only users with a broken PAC return DIRECT and also vanish from Insights; tunneled Client Connector users would still appear. That split is the PAC tell.

   Green success on each ticket

- 4812: Web row names DLP-PII-OWA-Attach (or whatever you wrote) as Blocked Policy Name.

- 4813: Hop View names the hop; ZDX Score recovers after the path change, without a new URL rule.

- 4814: User Activity Connection Status succeeds on the intended Policy + Connector.

- 4815: SIEM search over 12 months returns the NSS Web fields, not an Insights “no data” pane.

- 4816: Tunnel Insights shows the tunnel up at the same timestamp the icon turns green.

## 7. Traps + close-the-ticket proof

   Proof · named field, then Closed

   Notice: the close is a named column on a timestamp, not a screenshot of the user’s Salesforce tab.

     Trap  What it looks like  First check

      Treating Allowed as healthy  User says slow; you keep editing URL rules  Policy Action = Allowed → leave policy. ZDX Hop View.
      Web Insights for a private FQDN  Empty Web log, Jira still dead  ZPA Diagnostics · User Activity.
      ZDX deployed, no probe for that app  Score pane says no data while Slack burns  Configuration → probes. Workday / custom apps are opt-in.
      Trusting ZDX Score without Hop View  Score is low; you blame ZIA  Score is a rollup. The hop (or device CPU / Wi-Fi) is the cause.
      Calling ZPA’s stream “NSS”  SIEM has ZIA Web and nothing for ZPA  ZIA = NSS. ZPA = LSS (Log Streaming Service).
      NSS ingest, no parsers  Auditor ask fails even though EPS is healthy  Install the vendor content pack; search the official Web feed fields.
      Tunnel-down hunted in Web  No rows, you assume “policy dropped everything”  Tunnel Insights. Then 443 egress / PAC / trusted-network disable.
      Activate without a re-query  ZPA policy “fixed,” user still blocked  Re-run User Activity. A higher-priority Policy or  PosturesMiss  may still win.

   Pilot checklist (weekly, not after the Sev-2)

- Web Insights saved filter (User + last 1 hour + Policy Action = Blocked) returns rows.

- Tunnel Insights shows current Client Connector tunnels for a known location.

- One ZPA User Activity query for a known healthy app returns Connection Status success + the expected Connector.

- SIEM: events from the NSS Web feed in the last 15 minutes > 0. Alert if that count is 0.

- ZDX: Salesforce / Teams / your top-5 apps each have a Cloud Path probe; Hop View is not empty.

   Say this out loud

   Insights tells me the verdict. Nanolog plus NSS keeps the verdict. ZPA Diagnostics names the Connector. ZDX names the hop. I do not change a URL rule because a hop died.

## Knowledge check

   Six judgment items. Each one maps to a ticket or a trap. Check answers, then Reset if you picked the wrong surface.

       Q1
       APAC reports Salesforce is slow. Web Insights  Policy Action  is Allowed. Which first tool answers where the path died?

           Web Insights → Blocked Policy Name
           ZPA Diagnostics → User Activity
           ZDX Cloud Path → Hop View (latency / packet loss)
           NSS 12-month SIEM search

       Correct:  c . Allowed means policy is not the layer. Hop View is the official Cloud Path visualisation of latency and loss. Re-read §3 and INC-4813.

       Q2
       A new DLP rule shipped an hour ago. Outlook Web opens; attachments fail. Which proof field closes INC-4812?

           Web Insights: Policy Action + Blocked Policy Name on the attachment transaction
           ZDX Score for Exchange Online
           ZPA Connection Status
           Tunnel Insights Client Tunnel IP

       Correct:  a . Official Web Insights columns. ZPA is private apps. ZDX is experience. Tunnel is “is the client even up.” Re-read Side A and INC-4812.

       Q3
       The auditor wants every DLP trigger for PII, by user, for the last 12 months, joined with EDR. What is the right store?

           Upgrade the Insights SKU and stay in the GUI
           Nanolog streamed by NSS into the SIEM, with the Web feed parsed
           Weekly CSV export from Web Insights
           ZDX Hop View history

       Correct:  b . Insights queries Nanolog but retention ages out (SKU-dependent). NSS is the official streamer for long SIEM retention and joins. Re-read Side C and INC-4815.

       Q4
       A contractor cannot reach  jira.corp.internal . Client Connector says no connection. First tool + proof?

           Web Insights URL Category
           ZPA Logs → Insights → Diagnostics → User Activity: Connection Status + Policy + Connector
           ZDX Web probe for jira.corp.internal
           NSS Tunnel feed only

       Correct:  b . Official path and User Activity fields. Web Insights is ZIA internet/SaaS. ZDX hop path does not replace a policy/Connector decision. Re-read Side B and INC-4814.

       Q5
       Web Insights Policy Action is Allowed. The user still says “Zscaler is slow.” What do you do first?

           Disable the URL Allow that matched
           Force re-authentication for the org
           Open ZPA User Activity because every SaaS is really ZPA
           Leave policy alone. Open ZDX Cloud Path Hop View

       Correct:  d . Allowed is not a healthy path. Changing URL policy adds risk and cannot name a hop. Re-read the diamond in §3 and the first trap in §7.

       Q6
       A branch reports Client Connector red on every laptop since a 02:00 firewall change. Web Insights is empty. Which Insights type first?

           Web Insights — a URL category must have blocked the internet
           Tunnel Insights Logs — Client Tunnel IP and up/down time, then 443 egress
           ZPA User Activity — Jira is probably also down
           ZDX hosted probe only — hop count will explain a red icon

       Correct:  b . Empty Web is the clue the tunnel never landed. Tunnel Insights is a documented Insights Logs type. Simultaneous 02:00 failure points at egress, not staggered auth. Re-read Side A step 3 and INC-4816.

       Check answers
       Reset

## Sources

- Zscaler Help — About Insights Logs (Analytics → Insights Logs; Web, Firewall, DNS, Tunnel, and sibling types)

- Zscaler Help — Web Insights Logs: Columns ( Policy Action , Blocked Policy Name , URL Category , Cloud Application , Cloud Application Class )

- Zscaler Help — Web Insights Logs: Filters

- Zscaler Help — Firewall Insights Logs: Columns ( Action , Rule Name , Client Tunnel IP , Zscaler Client Connector Tunnel Version )

- Zscaler Help — Tunnel Insights Logs: Columns

- Zscaler Help — Understanding Nanolog Streaming Service

- Zscaler Help — NSS Feed Output Format: Web Logs

- Zscaler Help — Adding TCP NSS Feeds (Administration → Nanolog Streaming Service)

- Zscaler Help — Accessing User Activity Diagnostics (Logs → Insights → Diagnostics · Log Type: User Activity)

- Zscaler Help — Accessing User Status Diagnostics

- Zscaler Help — Understanding Private Access Session Status Codes

- Zscaler Help — About User Activity Log Fields / LSS format ( ConnectionStatus , Policy , Connector , InternalReason )

- Zscaler Help — Evaluating the Cloud Path (Hop View, latency, packet loss)

- Zscaler Help — Cloud Path Errors

- Zscaler Help — Understanding the ZDX Score

- Zscaler Help — ZDX troubleshooting / remediation

- Zscaler Help — Configuring Zscaler Managed / Hosted Probes (Hop Count)

 Related:  Lesson 12 · Isolation + SIPA  ·  Lesson 5 · URL + Cloud App (Web Insights proof)  ·  Lesson 9 · ZPA architecture  ·  Lesson 10 · ZPA Connectors  ·  Lesson 14 · ZDTA + interview  ·  Authentication (identity before logs)

---
Cite this Techclick lesson with the source URL. Do not invent fees, batch dates, or job guarantees.
Browse all lessons: https://ai.techclick.in/blogs
AI index: https://ai.techclick.in/llms.txt
