Zscaler
Use Zscaler Digital Experience (ZDX) metrics to define a threshold for application experience, Web Probe performance, or CloudPath network performance. First, add a Zscaler data source.
Zscaler parameters and supported features in Nobl9
- General support:
- Release channel:
Beta
- Connection method: Agent, Direct
- Replay and SLI Analyzer: Historical data limit 13 days
- Event logs: Supported
- Query checker: Not supported
- Test metric: Supported
- Query parameters retrieval: Supported
- Timestamp cache persistence: Supported
- Connection method: Agent, Direct
- Query parameters:
- Query interval: 10 min
- Query delay: 20 min
- Jitter: 15 sec
- Timeout: 60 sec
- Query delay: 20 min
- Agent details and minimum required versions for supported features:
- Replay and SLI Analyzer: 0.115.0-beta
- Query parameters retrieval: 0.115.0-beta
- Test metric: 0.115.0-beta
- Timestamp cache persistence: 0.115.0-beta
- Query parameters retrieval: 0.115.0-beta
- Additional notes:
- Requires Nobl9 agent 0.115.0-beta or a later beta release.
- Threshold metrics only. Historical availability depends on your ZDX retention entitlement.
Supported metrics
Each query requires both a report type and a metric. Zscaler supports threshold (rawMetric) SLOs only; its reports do not provide the good and total event counts required for ratio (countMetrics) SLOs.
| Report type | Metric | Meaning and unit | Required IDs | Optional selectors |
|---|---|---|---|---|
application | score | ZDX score, 0–100 | appId | locationId |
application | pft | Page fetch time, milliseconds | appId | locationId |
web-probe | pft | Page fetch time, milliseconds | appId, deviceId, probeId | None |
web-probe | ttfb | Time to first byte, milliseconds | appId, deviceId, probeId | None |
web-probe | dns | DNS time, milliseconds | appId, deviceId, probeId | None |
web-probe | availability | Web Probe availability, percent | appId, deviceId, probeId | None |
cloudpath | latency | Network latency, milliseconds | appId, deviceId, probeId | legSrc and legDst |
cloudpath | loss | Packet loss, percent | appId, deviceId, probeId | legSrc and legDst |
All IDs must be positive integers. Enter numeric IDs in YAML without quotation marks. Obtain the application, location, device, and probe IDs from your ZDX configuration or API reports. Device and probe IDs are entered manually in Nobl9.
Application reports
Application reports contain values aggregated by ZDX for the application and optional location. Omit locationId to include all locations. Application queries do not accept device, probe, or CloudPath segment selectors.
A threshold such as score > 65 evaluates the application's aggregated score over time. It does not measure the percentage of users whose individual scores exceed 65.
Web Probe and CloudPath reports
Probe queries select one probe on one device and do not accept locationId. Nobl9 uses the selected time series without aggregating across devices or probes.
For CloudPath, supply both legSrc and legDst or omit both. Values must exactly match the leg_src and leg_dst labels in the ZDX response, including case. Omitting both selects end/end. Packet loss is a network loss measurement, not path availability.
Creating SLOs with Zscaler
- Nobl9 Web
- YAML
- Navigate to Service Level Objectives and click +.
- Select the service and your Zscaler data source.
- Choose whether to retrieve historical data with Replay. The default period is 7 days, with a maximum of 13 days subject to your ZDX retention.
- Use a Threshold metric and select the Report type and metric from the supported metrics.
- Enter the Application ID. For application reports, optionally enter a Location ID. For probe reports, enter the Device ID and Probe ID.
- For CloudPath, optionally enter both Source segment (legSrc) and Destination segment (legDst). Leave both empty for
end/end. - Use Test metric to check that the selected report returns the expected values.
[screenshot needed: Zscaler SLO form with report type, metric, IDs, and CloudPath segment selectors]
- Define the Time window for your SLO:
- Rolling time windows constantly move forward as time passes. This type can help track the most recent events.
- Calendar-aligned time windows are usable for SLOs intended to map to business metrics measured on a calendar-aligned basis.
- Configure the Error budget calculation method and Objectives:
- Occurrences method counts good attempts against the count of total attempts.
- Time Slices method measures how many good minutes were achieved (when a system operates within defined boundaries) during a time window.
- You can define up to 12 objectives for an SLO.
Similar threshold values for objectivesTo use similar threshold values for different objectives in your SLO, we recommend differentiating them by setting varying decimal points for each objective.
For example, if you want to use threshold value1for two objectives, set it to1.0000001for the first objective and to1.0000002for the second one. - Add the Display name, Name, and other settings for your SLO:
- Name identifies your SLO in Nobl9. After you save the SLO, its name becomes read-only.
Use only lowercase letters, numbers, and dashes. - Select No data anomaly alert to receive notifications when your SLO stops reporting data for a specified period:
- Choose up to five supported Alert methods.
- Specify the delay period before Nobl9 sends an alert about the missing data.
From 5 minutes to 31 days. Default: 15 minutes
- Add alert policies, labels, and links, if required.
Limits per SLO: 20 alert policies or links, 30 labels.
- Name identifies your SLO in Nobl9. After you save the SLO, its name becomes read-only.
- Click CREATE SLO
The following examples use an Agent named zscaler in the default project. Replace the IDs with values from your ZDX reports and set service to an existing Nobl9 service. For a Direct connection, change spec.indicator.metricSource.kind to Direct and use your Direct data source's name and project.
Choose a sample, save it as zscaler-slo.yaml, and apply it with sloctl apply -f zscaler-slo.yaml. Adjust the objective's threshold and target to your requirements.
- Application score
- Web Probe availability
- CloudPath latency
apiVersion: n9/v1alpha
kind: SLO
metadata:
name: zscaler-application
project: default
spec:
service: user-experience
indicator:
metricSource:
name: zscaler
project: default
kind: Agent
budgetingMethod: Occurrences
objectives:
- name: acceptable-performance
displayName: Application score above 65
target: 0.99
value: 65
op: gt
primary: true
rawMetric:
query:
zscaler:
type: application
metric: score
appId: 12345
locationId: 45678
timeWindows:
- unit: Day
count: 7
isRolling: true
apiVersion: n9/v1alpha
kind: SLO
metadata:
name: zscaler-web-probe
project: default
spec:
service: user-experience
indicator:
metricSource:
name: zscaler
project: default
kind: Agent
budgetingMethod: Occurrences
objectives:
- name: acceptable-performance
displayName: Web Probe reports full availability
target: 0.99
value: 100
op: gte
primary: true
rawMetric:
query:
zscaler:
type: web-probe
metric: availability
appId: 12345
deviceId: 67890
probeId: 13579
timeWindows:
- unit: Day
count: 7
isRolling: true
apiVersion: n9/v1alpha
kind: SLO
metadata:
name: zscaler-cloudpath
project: default
spec:
service: user-experience
indicator:
metricSource:
name: zscaler
project: default
kind: Agent
budgetingMethod: Occurrences
objectives:
- name: acceptable-performance
displayName: CloudPath latency at most 200 ms
target: 0.99
value: 200
op: lte
primary: true
rawMetric:
query:
zscaler:
type: cloudpath
metric: latency
appId: 12345
deviceId: 67890
probeId: 13579
legSrc: end
legDst: end
timeWindows:
- unit: Day
count: 7
isRolling: true
YAML field reference
| Field | Type | Description |
|---|---|---|
apiVersion Mandatory | string | API version. Use n9/v1alpha |
kind Mandatory | string | The resource type. Use SLO |
| Metadata | ||
metadata.name Mandatory | string | Name identifier for the SLO. Use only lowercase alphanumeric characters |
metadata.displayName | string | User-friendly SLO name |
metadata.project Mandatory | string | The name identifier of the project where you need to host your SLO |
metadata.labels | object (map: string[]) | Grouping labels for filtering or viewing |
metadata.annotations | object (map: string) | Flat string annotations |
| Spec | ||
spec.description | string | SLO description |
spec.indicator.metricSource.name Mandatory | string | Data source name |
spec.indicator.metricSource.project Mandatory | string | Project containing the data source |
spec.indicator.metricSource.kind Mandatory | string | Data source connection method. Can be Agent or Direct |
spec.budgetingMethod Mandatory | enum | Error budget calculation method. Can be Occurrences or Time slices |
spec.objectives Mandatory | array | Your SLO objective definition, up to 12 objectives per SLO. |
spec.objectives[].displayName | string | User-friendly objective name |
spec.objectives[].value Mandatory | number | Data point values that is considered "good" (e.g., 200.0).In SLOs with two or more objectives, keep each objective's value unique. In ratio ( count) metrics, value is retained for legacy purposes. |
spec.objectives[].name Mandatory | string | Name identifier for this objective |
spec.objectives[].op Mandatory | string (enum) | Operator for objective. One of:lte (less than or equal to)lt (less than)gte (greater than or equal to)gt (greater than) |
spec.objectives[].target Mandatory | float | The percentage of the good minutes or occurrences that must meet the desired performance (e.g., is the target is 0.95, the good performance is expected to be observed in at least 95% of the time window) |
spec.objectives[].rawMetric/.countMetric Mandatory | object | The metric type indicator. Set:rawMetric for a threshold metriccountMetric for a ratio metric.A ratio metric requires the additional fields: countMetric.incremental (boolean) the data count methodcountMetric.good/.bad and countMetric.total a numerator and denominator queries |
spec.objectives[].countMetric.incremental Mandatory | boolean | The data count method for a ratio (countMetric) metric type |
spec.objectives[].primary | boolean | The indicator of a primary SLO objective |
spec.service Mandatory | string | The name identifier of a service to host this SLO. The service must exist in the project specified in metadata.project |
spec.timeWindows Mandatory | array | Defines SLO time window for error budget calculation. Set: isRolling: true for the rolling time window typeisRolling: false for the calendar-aligned type |
spec.timeWindows.unit Mandatory | integer | The time window units. One of:Day | Hour | Minute for the rolling time windowYear | Quarter | Month | Week | Day for the calendar-aligned time window |
spec.timeWindows.count Mandatory | integer | The number of units in a time window |
spec.timeWindows.startTime | string | Mandatory for calendar-aligned time windows. Date and time in the format YYYY-MM-DDTHH:mm:ss |
spec.timeWindows.timeZone | string | Mandatory for calendar-aligned time-windows. A valid IANA Time Zone Database name |
spec.timeWindows.isRolling Mandatory | boolean | true for the rolling time window typefalse for the calendar-aligned type |
spec.alertPolicies | array | The name identifiers of alert policies to be linked to this SLO (must be from the same project as the SLO). Up to 20 alert policies per SLO. |
spec.attachments | array | Links to any additional attributes of this SLO |
spec.anomalyConfig | object | Settings for a manual no data anomaly detection rule |
spec.noData.alertMethods | array | List of alert methods for no-data anomaly. Up to five alert methods per SLO. Every alert method must have the name and project fields |
spec.noData.alertAfter | string | Waiting time before sending a no-data notification. Must be 5m to 31d.Default: 15m |
spec.noData.treatZeroAsNoData | boolean | Opt-in setting for manual no-data anomaly detection. When set to true, zero-valued points are treated as no data for this alerting flow.Default: false |
| Zscaler fields under rawMetric.query.zscaler | ||
typeMandatory | string | application, web-probe, or cloudpath. |
metricMandatory | string | A metric supported by the selected report type. See the supported metrics table. |
appIdMandatory | integer | Positive application ID. |
locationIdOptional | integer | Positive location ID. Only supported for application reports. Omit to include all locations. |
deviceIdOptional | integer | Positive device ID. Required for web-probe and cloudpath; forbidden for application. |
probeIdOptional | integer | Positive probe ID. Required for web-probe and cloudpath; forbidden for application. |
legSrcOptional | string | CloudPath only. Exact nonempty leg_src label from the response. Defaults to end when both selectors are omitted. |
legDstOptional | string | CloudPath only. Exact nonempty leg_dst label from the response. Defaults to end when both selectors are omitted. |
Data handling
Nobl9 selects one matching time series. If the requested metric or CloudPath segment is absent, the query returns no data. Nobl9 does not substitute another series or fill the gap with zero. Negative samples are excluded; valid zeros and original timestamps are preserved. An ambiguous response with multiple matching series is an error.
ZDX metrics use five-minute resolution. The default query interval is 10 minutes and the default query delay is 20 minutes. For request quotas and historical retrieval boundaries, see Zscaler limitations.