# Zscaler ZPA log ingestion via QRadar

For customers who already have Zscaler Private Access (ZPA) LSS logs flowing into QRadar for other reasons, Vectra is providing this additional set of instructions for how to setup QRadar forwarding of these logs to Detect.

Vectra recommends that customers also read the information in the following article that covers ZPA LSS Log Ingestion directly to Cognito Detect without using QRadar as an intermediary:

[https://support.vectra.ai/s/article/KB-VS-1058](https://docs.vectra.ai/configuration/coverage/remote-users/zscaler-zpa)​​​​​​​

### Instructions

#### Step 1

Within the QRadar Admin Panel, click on Forwarding Destinations under the System Configuration section.

![](https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2Fgit-blob-3d2a40fdf999960cbfa2b2c562a993f23516dffc%2Fa5e570af1869b0127f3f68454b1cb0fd636fc44f49dd5640273d69759a02cafe.png?alt=media)

Add an entry with the Destination Address as your Cognito Detect Brain.

* Event Format = Payload,
* Destination Port = 4639
* Protocol = TCP
* It is important that the option “Prefix a syslog header if it is missing or invalid” is **NOT** enabled

![](https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2Fgit-blob-e79268e8b429eac901a6c99fd79b58f7b8dc6874%2F70e34b2c1201d45290451361db1725667b828b52ef2c113b5890b06f9b740265.png?alt=media)

#### Step 2

* Next, within the Admin Panel (see screenshot above), click on Routing Rules
* Add an entry to forward the ZPA logs to the Detect Brain (screenshots below)
  * If event filtering is desired for specific QIDs, create that filter in the **Event Filters** section
* Select the appropriate event collector where the ZPA logs are already being sent
* Under Routing Options, check the box for Forward and select the Forwarding Destination created in the first step
* Finally, check the box for Log Only, this will forward the original payload with no QRadar log wrapper
* Click Save and forwarding to Detect should be complete

![](https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2Fgit-blob-421fe47eda48d13bb435edbf8180083b85e8ab33%2F2a39594903f36849862c0ee73b6bb627a07489da6bfa95e67666b397e877fef7.png?alt=media)

![](https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2Fgit-blob-472bd096479d0588f63b1ece2a0893f01f574338%2F6aa3f4dfc1583da4605a4691ae27942f4059de43a0a37b2e3c9c92f3da92ece6.png?alt=media)

![](https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2Fgit-blob-a304586c47d2adf0b94664528865159e66f4302e%2F8f8d9fc1b259b5e12d71a7256b8fe8bbb7f01f1639e65cfc327514e6b3e77e19.png?alt=media)

![](https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2Fgit-blob-d3c8566e21a1a7ddf7df4e48ce1ef37c1bcc1e41%2F1d45676458c6a78144535628ba0c4e5e130f4f3936f3b29c209ffa5f86b3a251.png?alt=media)

Status of forwarding to Detect can be seen at **Settings > External Connectors > Zscaler Private Access (ZPA)**
