Zscaler
Connect Zscaler Digital Experience (ZDX) to Nobl9 through OneAPI to create SLOs from application scores, Web Probe measurements, and CloudPath metrics.
Zscaler parameters and supported features in Nobl9
- General support:
- Release channel:
Beta
- Connection method: Agent, Direct
- Replay and SLI Analyzer: Historical data limit 13 days
- Event logs: Supported
- Query checker: Not supported
- Test metric: Supported
- Query parameters retrieval: Supported
- Timestamp cache persistence: Supported
- Connection method: Agent, Direct
- Query parameters:
- Query interval: 10 min
- Query delay: 20 min
- Jitter: 15 sec
- Timeout: 60 sec
- Query delay: 20 min
- Agent details and minimum required versions for supported features:
- Replay and SLI Analyzer: 0.115.0-beta
- Query parameters retrieval: 0.115.0-beta
- Test metric: 0.115.0-beta
- Timestamp cache persistence: 0.115.0-beta
- Query parameters retrieval: 0.115.0-beta
- Additional notes:
- Requires Nobl9 agent 0.115.0-beta or a later beta release.
- Threshold metrics only. Historical availability depends on your ZDX retention entitlement.
Zscaler support is available starting with Nobl9 agent 0.115.0-beta. Use this version or a later beta release.
Authentication
Use a Zscaler OneAPI client with access to the ZDX API resource and permission to read the application and probe reports you want to monitor. See Zscaler OneAPI authentication for client setup. Legacy ZDX API keys are not supported.
You need the following values:
- Vanity domain: the tenant label only. For
example.zslogin.net, enterexample. Use 1–63 lowercase letters, digits, or hyphens, starting and ending with a letter or digit. Do not includehttps://or.zslogin.net. - Client ID and Client secret: credentials for the same OneAPI client in that tenant.
For an Agent connection, provide the credentials through the ZSCALER_CLIENT_ID and ZSCALER_CLIENT_SECRET environment variables in your agent deployment. Keep the Nobl9 N9_CLIENT_ID and N9_CLIENT_SECRET credentials from the installation instructions as well: these authenticate the agent to Nobl9.
For Kubernetes, add the following entries to the agent container's env list. Create a Secret named zscaler-oneapi in the agent's namespace with the client-id and client-secret keys containing your OneAPI credentials.
env:
- name: ZSCALER_CLIENT_ID
valueFrom:
secretKeyRef:
name: zscaler-oneapi
key: client-id
- name: ZSCALER_CLIENT_SECRET
valueFrom:
secretKeyRef:
name: zscaler-oneapi
key: client-secret
For Docker, export ZSCALER_CLIENT_ID and ZSCALER_CLIENT_SECRET in your shell and add -e ZSCALER_CLIENT_ID -e ZSCALER_CLIENT_SECRET to the agent command from Nobl9.
For a Direct connection, enter both credentials when creating the data source. Nobl9 masks both values in API responses. When updating the data source through YAML or the API, omit either credential to preserve its stored value. You can rotate one credential without resubmitting the other.
Adding Zscaler as a data source
Direct connection method
- Nobl9 Web
- YAML
- Navigate to Integrations > Data sources.
- Click
.
- Click your required Source tile.
- Choose Direct.
-
Select the Beta release channel.
-
Enter the Vanity domain, Client ID, and Client secret.
-
Select a Project and enter a Name. Optionally add a Display Name and Description.
-
Set Query delay to 20 minutes, or adjust it for your data availability.
-
Configure the Maximum period for historical data retrieval (up to 13 days) and Default period for historical data retrieval (7 days by default). Use shorter periods if required by your ZDX retention entitlement.
-
Click Add Data Source.
[screenshot needed: Zscaler Direct configuration showing the vanity domain, credential fields, and Beta release channel]
Replace the tenant and credential placeholders in this definition, then apply it with sloctl apply -f zscaler-direct.yaml.
apiVersion: n9/v1alpha
kind: Direct
metadata:
name: zscaler
displayName: Zscaler Direct
project: default
spec:
releaseChannel: beta
zscaler:
vanityDomain: example
clientId: <ZSCALER_CLIENT_ID>
clientSecret: <ZSCALER_CLIENT_SECRET>
historicalDataRetrieval:
maxDuration:
value: 13
unit: Day
defaultDuration:
value: 7
unit: Day
queryDelay:
value: 20
unit: Minute
| Field | Type | Description |
|---|---|---|
queryDelay.unitMandatory | enum | Specifies the unit for the query delay. Possible values: Second | Minute. • Check query delay documentation for default unit of query delay for each source. |
queryDelay.value Mandatory | numeric | Specifies the value for the query delay. • Must be a number less than 1440 minutes (24 hours). • Check query delay documentation for default unit of query delay for each source. |
logCollectionEnabledOptional | boolean | Optional. Defaults to false. Set to true if you'd like your direct to collect event logs. Contact us to activate it. |
releaseChannelMandatory | enum | Specifies the release channel. Accepted values: beta | stable. |
| Source-specific fields | ||
zscaler.vanityDomainMandatory | string | Your OneAPI tenant label, for example example for example.zslogin.net. |
zscaler.clientIdMandatory | string | OneAPI client ID, required on creation. Omit on update to preserve the stored value. |
zscaler.clientSecretMandatory | string | OneAPI client secret, required on creation. Omit on update to preserve the stored value. |
Agent connection method
- Nobl9 Web
- YAML
- Navigate to Integrations > Data sources.
- Click
.
- Click your required Source tile.
- Choose Agent.
-
Select the Beta release channel.
-
Enter the Vanity domain.
-
Select a Project and enter a Name. Optionally add a Display Name and Description.
-
Set Query delay to 20 minutes, or adjust it for your data availability.
-
Configure the Maximum period for historical data retrieval (up to 13 days) and Default period for historical data retrieval (7 days by default). Use shorter periods if required by your ZDX retention entitlement.
-
Click Add Data Source.
-
Deploy the agent using the installation instructions and include the Zscaler environment variables.
[screenshot needed: Zscaler Agent configuration and installation instructions with OneAPI credential variables]
Replace the tenant label, then apply the definition with sloctl apply -f zscaler-agent.yaml. Deploy the agent using the installation instructions in Nobl9 and add the Zscaler environment variables.
apiVersion: n9/v1alpha
kind: Agent
metadata:
name: zscaler
displayName: Zscaler Agent
project: default
spec:
releaseChannel: beta
zscaler:
vanityDomain: example
historicalDataRetrieval:
maxDuration:
value: 13
unit: Day
defaultDuration:
value: 7
unit: Day
queryDelay:
value: 20
unit: Minute
| Field | Type | Description |
|---|---|---|
queryDelay.unitMandatory | enum | Specifies the unit for the query delay. Possible values: Second | Minute. • Check query delay documentation for default unit of query delay for each source. |
queryDelay.value Mandatory | numeric | Specifies the value for the query delay. • Must be a number less than 1440 minutes (24 hours). • Check query delay documentation for default unit of query delay for each source. |
logCollectionEnabledOptional | boolean | Optional. Defaults to false. Set to true if you'd like your direct to collect event logs. Contact us to activate it. |
releaseChannelMandatory | enum | Specifies the release channel. Accepted values: beta | stable. |
| Source-specific fields | ||
zscaler.vanityDomainMandatory | string | Your OneAPI tenant label, for example example for example.zslogin.net. Provide credentials in the agent deployment. |
Query parameters
Both connection methods use these defaults:
| Parameter | Default |
|---|---|
| Query interval | 10 minutes |
| Query delay | 20 minutes |
| Jitter | 15 seconds |
| Timeout | 60 seconds |
The query delay allows time for ZDX reports to become available. You can configure it in the data source settings or through spec.queryDelay. See Query parameters for details about collection timing.
Limitations
Metrics and selectors
Zscaler supports threshold SLOs only. Each query selects one application series or one probe series on one device. Device and probe IDs must be supplied manually; Nobl9 does not discover them or combine results across devices or probes. See Creating Zscaler SLOs for supported metrics and selectors.
Request limits
By default, Nobl9 applies all of the following limits to metric requests for each Zscaler data source:
| Limit | Default |
|---|---|
| Requests per minute | 30 |
| Requests per hour | 1,000 |
| Requests per 24 hours | 10,000 |
These limits apply together, including during historical retrieval. Token requests are separate from this metric request quota. Separate Nobl9 data sources have separate counters, even when they use the same OneAPI credentials; Zscaler can still apply shared tenant quotas. Contact Nobl9 support if your ZDX entitlement requires different limits.
Historical retrieval
Replay and SLI Analyzer default to 7 days of history and allow a maximum configured period of 13 days. Actual data availability depends on your ZDX retention entitlement.
Choose a range within your available retention. Older data can expire while retrieval is queued or running, so a request at the retention boundary can fail.