Skip to main content

Zscaler

Reading time: 0 minute(s) (0 words)

Use Zscaler Digital Experience (ZDX) metrics to define a threshold for application experience, Web Probe performance, or CloudPath network performance. First, add a Zscaler data source.

Nobl9 integration with Zscaler is available only in the Beta release channel.
Zscaler parameters and supported features in Nobl9
General support:
Release channel: Beta
Connection method: Agent, Direct
Replay and SLI Analyzer: Historical data limit 13 days
Event logs: Supported
Query checker: Not supported
Test metric: Supported
Query parameters retrieval: Supported
Timestamp cache persistence: Supported

Query parameters:
Query interval: 10 min
Query delay: 20 min
Jitter: 15 sec
Timeout: 60 sec

Agent details and minimum required versions for supported features:
Replay and SLI Analyzer: 0.115.0-beta
Query parameters retrieval: 0.115.0-beta
Test metric: 0.115.0-beta
Timestamp cache persistence: 0.115.0-beta

Additional notes:
Requires Nobl9 agent 0.115.0-beta or a later beta release.
Threshold metrics only. Historical availability depends on your ZDX retention entitlement.

Supported metrics​

Each query requires both a report type and a metric. Zscaler supports threshold (rawMetric) SLOs only; its reports do not provide the good and total event counts required for ratio (countMetrics) SLOs.

Report typeMetricMeaning and unitRequired IDsOptional selectors
applicationscoreZDX score, 0–100appIdlocationId
applicationpftPage fetch time, millisecondsappIdlocationId
web-probepftPage fetch time, millisecondsappId, deviceId, probeIdNone
web-probettfbTime to first byte, millisecondsappId, deviceId, probeIdNone
web-probednsDNS time, millisecondsappId, deviceId, probeIdNone
web-probeavailabilityWeb Probe availability, percentappId, deviceId, probeIdNone
cloudpathlatencyNetwork latency, millisecondsappId, deviceId, probeIdlegSrc and legDst
cloudpathlossPacket loss, percentappId, deviceId, probeIdlegSrc and legDst

All IDs must be positive integers. Enter numeric IDs in YAML without quotation marks. Obtain the application, location, device, and probe IDs from your ZDX configuration or API reports. Device and probe IDs are entered manually in Nobl9.

Application reports​

Application reports contain values aggregated by ZDX for the application and optional location. Omit locationId to include all locations. Application queries do not accept device, probe, or CloudPath segment selectors.

A threshold such as score > 65 evaluates the application's aggregated score over time. It does not measure the percentage of users whose individual scores exceed 65.

Web Probe and CloudPath reports​

Probe queries select one probe on one device and do not accept locationId. Nobl9 uses the selected time series without aggregating across devices or probes.

For CloudPath, supply both legSrc and legDst or omit both. Values must exactly match the leg_src and leg_dst labels in the ZDX response, including case. Omitting both selects end/end. Packet loss is a network loss measurement, not path availability.

Creating SLOs with Zscaler​

  1. Navigate to Service Level Objectives and click +.
  2. Select the service and your Zscaler data source.
  3. Choose whether to retrieve historical data with Replay. The default period is 7 days, with a maximum of 13 days subject to your ZDX retention.
  4. Use a Threshold metric and select the Report type and metric from the supported metrics.
  5. Enter the Application ID. For application reports, optionally enter a Location ID. For probe reports, enter the Device ID and Probe ID.
  6. For CloudPath, optionally enter both Source segment (legSrc) and Destination segment (legDst). Leave both empty for end/end.
  7. Use Test metric to check that the selected report returns the expected values.

[screenshot needed: Zscaler SLO form with report type, metric, IDs, and CloudPath segment selectors]

  1. Define the Time window for your SLO:
  2. Configure the Error budget calculation method and Objectives:
    • Occurrences method counts good attempts against the count of total attempts.
    • Time Slices method measures how many good minutes were achieved (when a system operates within defined boundaries) during a time window.
    • You can define up to 12 objectives for an SLO.

    • Similar threshold values for objectives
      To use similar threshold values for different objectives in your SLO, we recommend differentiating them by setting varying decimal points for each objective.
      For example, if you want to use threshold value 1 for two objectives, set it to 1.0000001 for the first objective and to 1.0000002 for the second one.
  3. Add the Display name, Name, and other settings for your SLO:
    • Name identifies your SLO in Nobl9. After you save the SLO, its name becomes read-only.
      Use only lowercase letters, numbers, and dashes.
    • Select No data anomaly alert to receive notifications when your SLO stops reporting data for a specified period:
      • Choose up to five supported Alert methods.
      • Specify the delay period before Nobl9 sends an alert about the missing data.
        From 5 minutes to 31 days. Default: 15 minutes
    • Add alert policies, labels, and links, if required.
      Limits per SLO: 20 alert policies or links, 30 labels.
  4. Click CREATE SLO.

  5. SLO configuration use case
    Check the SLO configuration use case for a real-life SLO example.

Data handling​

Nobl9 selects one matching time series. If the requested metric or CloudPath segment is absent, the query returns no data. Nobl9 does not substitute another series or fill the gap with zero. Negative samples are excluded; valid zeros and original timestamps are preserved. An ambiguous response with multiple matching series is an error.

ZDX metrics use five-minute resolution. The default query interval is 10 minutes and the default query delay is 20 minutes. For request quotas and historical retrieval boundaries, see Zscaler limitations.

Check out these related guides and references: