This version uses Splunk SDK for Python (2.0.2)
fixing zsten compatibility issue
Fixing Splunk cloud compatibility issues
Bug fixes related to app compat testing
Fixed support for proxies configured in the TA settings
Regression fix - removed predefined-testing stanzas from inputs.conf
Updated to latest Splunk SDK as per update in Add-On Builder 4.0; maintain Splunk Cloud compatibility
Fixed proxy support - no longer needs code changes, functions with Splunk UI
CIM Corrections
Added Source-type for Zscaler DLP Incident Receiver
Change in how Audit logs events are ingested - each event is logged separately, not nested in the report/JSON
Removed predefined ZDMEO::Beta inputs accidentally inserted in previous release
Added ZscalerGov back into Cloud Types, this is a repaired regression
Note - Release 3.0.3 - 3.0.5 were only released privately.
3.0.2 - Fixes an issues where ZIA Audit Logs were missing or duplicated in some corner cases
Modified to macro "z-metricis" to value of index=_metrics so as to pass app-inspect validation - you will still need to modify this for your metrics index as per the full doc
Zscaler's Technical Add-on for Splunk has been fully rebuilt in latest Splunk Add-On builder (needed to pass new app-inspect and cloud-vetting requirements)
New ! - Connector Heath - requires admin to bond to Metrics-type Splunk index (default expected is z-metrics, can change in macros.conf)
Zscaler's Technical Add-on for Splunk has been fully rebuilt in latest Splunk Add-On builder (needed to pass new app-inspect and cloud-vetting requirements)
New ! - Connector Heath - requires admin to bond to Metrics-type Splunk index (default expected is z-metrics, can change in macros.conf)
Added fix to prevent extraction in proxied URL field
NOTE: When upgrading to this versions of the TA prior to 2.1.0 you will need to recreate your sandbox and/or audit-log modular inputs as these now use Global Accounts as per requirements for Splunk Cloud. The process for creating these inputs has been updated in the supporting documentation which is available here: https://community.zscaler.com/t/zscaler-splunk-app-design-and-installation-documentation/4728
Added fixes to make macro edit more friendly
Disabled KV Auto-Extract on web/proxy sourcetype to event URL query string extrapolation & overwrite at search time.
Minor app.manifest config fix for Splunk App Inspect pass
This version of the TA contains fixes for Splunk Cloud appvetting, it is the first API enabled version of the TA to be available for Splunk Cloud usage.
NOTE: When upgrading to this versions of the TA you will need to recreate your sandbox and/or audit-log modular inputs as these now use Global Accounts as per requirements for Splunk Cloud. The process for creating these inputs has been updated in the supporting documentation which is available here: https://community.zscaler.com/t/zscaler-splunk-app-design-and-installation-documentation/4728
Minor fix - correctly added ZIA-tunnel sourcetype
2.0.2 - added transforms.conf stanza for sandbox lookup (needed for App Inspect pass)
Version 2.0.0
Added Modular Inputs for Zscaler API's
- Admin Audit Logs (ZIA)
- Cloud Sandbox detailed reports
Moved all macros into TA, removed from App
Added and cleaned CIM mapping
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.