Skip to main content

Zscaler

Reading time: 0 minute(s) (0 words)

Connect Zscaler Digital Experience (ZDX) to Nobl9 through OneAPI to create SLOs from application scores, Web Probe measurements, and CloudPath metrics.

Nobl9 integration with Zscaler is available only in the Beta release channel.
Zscaler parameters and supported features in Nobl9
General support:
Release channel: Beta
Connection method: Agent, Direct
Replay and SLI Analyzer: Historical data limit 13 days
Event logs: Supported
Query checker: Not supported
Test metric: Supported
Query parameters retrieval: Supported
Timestamp cache persistence: Supported

Query parameters:
Query interval: 10 min
Query delay: 20 min
Jitter: 15 sec
Timeout: 60 sec

Agent details and minimum required versions for supported features:
Replay and SLI Analyzer: 0.115.0-beta
Query parameters retrieval: 0.115.0-beta
Test metric: 0.115.0-beta
Timestamp cache persistence: 0.115.0-beta

Additional notes:
Requires Nobl9 agent 0.115.0-beta or a later beta release.
Threshold metrics only. Historical availability depends on your ZDX retention entitlement.
Beta agent version

Zscaler support is available starting with Nobl9 agent 0.115.0-beta. Use this version or a later beta release.

Authentication​

Use a Zscaler OneAPI client with access to the ZDX API resource and permission to read the application and probe reports you want to monitor. See Zscaler OneAPI authentication for client setup. Legacy ZDX API keys are not supported.

You need the following values:

  • Vanity domain: the tenant label only. For example.zslogin.net, enter example. Use 1–63 lowercase letters, digits, or hyphens, starting and ending with a letter or digit. Do not include https:// or .zslogin.net.
  • Client ID and Client secret: credentials for the same OneAPI client in that tenant.

For an Agent connection, provide the credentials through the ZSCALER_CLIENT_ID and ZSCALER_CLIENT_SECRET environment variables in your agent deployment. Keep the Nobl9 N9_CLIENT_ID and N9_CLIENT_SECRET credentials from the installation instructions as well: these authenticate the agent to Nobl9.

For Kubernetes, add the following entries to the agent container's env list. Create a Secret named zscaler-oneapi in the agent's namespace with the client-id and client-secret keys containing your OneAPI credentials.

Zscaler credentials in the agent container
env:
- name: ZSCALER_CLIENT_ID
valueFrom:
secretKeyRef:
name: zscaler-oneapi
key: client-id
- name: ZSCALER_CLIENT_SECRET
valueFrom:
secretKeyRef:
name: zscaler-oneapi
key: client-secret

For Docker, export ZSCALER_CLIENT_ID and ZSCALER_CLIENT_SECRET in your shell and add -e ZSCALER_CLIENT_ID -e ZSCALER_CLIENT_SECRET to the agent command from Nobl9.

For a Direct connection, enter both credentials when creating the data source. Nobl9 masks both values in API responses. When updating the data source through YAML or the API, omit either credential to preserve its stored value. You can rotate one credential without resubmitting the other.

Adding Zscaler as a data source​

Direct connection method​

  1. Navigate to Integrations > Data sources.
  2. Click .
  3. Click your required Source tile.
  4. Choose Direct.
  1. Select the Beta release channel.

  2. Enter the Vanity domain, Client ID, and Client secret.

  3. Select a Project and enter a Name. Optionally add a Display Name and Description.

  4. Set Query delay to 20 minutes, or adjust it for your data availability.

  5. Configure the Maximum period for historical data retrieval (up to 13 days) and Default period for historical data retrieval (7 days by default). Use shorter periods if required by your ZDX retention entitlement.

  6. Click Add Data Source.

[screenshot needed: Zscaler Direct configuration showing the vanity domain, credential fields, and Beta release channel]

Agent connection method​

  1. Navigate to Integrations > Data sources.
  2. Click .
  3. Click your required Source tile.
  4. Choose Agent.
  1. Select the Beta release channel.

  2. Enter the Vanity domain.

  3. Select a Project and enter a Name. Optionally add a Display Name and Description.

  4. Set Query delay to 20 minutes, or adjust it for your data availability.

  5. Configure the Maximum period for historical data retrieval (up to 13 days) and Default period for historical data retrieval (7 days by default). Use shorter periods if required by your ZDX retention entitlement.

  6. Click Add Data Source.

  7. Deploy the agent using the installation instructions and include the Zscaler environment variables.

[screenshot needed: Zscaler Agent configuration and installation instructions with OneAPI credential variables]

Query parameters​

Both connection methods use these defaults:

ParameterDefault
Query interval10 minutes
Query delay20 minutes
Jitter15 seconds
Timeout60 seconds

The query delay allows time for ZDX reports to become available. You can configure it in the data source settings or through spec.queryDelay. See Query parameters for details about collection timing.

Limitations​

Metrics and selectors​

Zscaler supports threshold SLOs only. Each query selects one application series or one probe series on one device. Device and probe IDs must be supplied manually; Nobl9 does not discover them or combine results across devices or probes. See Creating Zscaler SLOs for supported metrics and selectors.

Request limits​

By default, Nobl9 applies all of the following limits to metric requests for each Zscaler data source:

LimitDefault
Requests per minute30
Requests per hour1,000
Requests per 24 hours10,000

These limits apply together, including during historical retrieval. Token requests are separate from this metric request quota. Separate Nobl9 data sources have separate counters, even when they use the same OneAPI credentials; Zscaler can still apply shared tenant quotas. Contact Nobl9 support if your ZDX entitlement requires different limits.

Historical retrieval​

Replay and SLI Analyzer default to 7 days of history and allow a maximum configured period of 13 days. Actual data availability depends on your ZDX retention entitlement.

Choose a range within your available retention. Older data can expire while retrieval is queued or running, so a request at the retention boundary can fail.

Check out these related guides and references: