10.2 Audit Logs, Web & Mobile Insights, Scheduled Reports

Key Takeaways

  • Audit Logs record every administrative transaction across the Zscaler platform, capturing the administrator username, timestamp, source IP, action type (Create, Update, Delete, Activate), and pre/post configuration diffs.
  • The two-stage configuration model separates staging edits (Save) from production enforcement (Activate), generating distinct audit log entries for policy modification and cloud activation.
  • Web, Mobile, and Firewall Insights provide real-time, interactive multidimensional log analytics across Layer 3 through Layer 7 traffic flows.
  • ZPA User Activity and Diagnostic Logs provide granular session-level telemetry into private application access, App Connector reachability, and microsegmentation policy drops.
  • Scheduled Reports enable automated generation and encrypted email delivery of Executive Summaries, Bandwidth reports, and DLP compliance audits on a daily, weekly, or monthly cadence.
Last updated: August 2026

10.2 Audit Logs, Web & Mobile Insights, Scheduled Reports

Quick Answer: The Zscaler platform provides native, multi-tiered visibility divided into Audit Logs (tracking administrative configuration changes and policy activation diffs), Insights Engines (real-time interactive analytics across Web, Mobile, and Firewall traffic), and ZPA Diagnostic Logs (tracking microsegmented private app transactions). For compliance and executive oversight, administrators configure Scheduled Reports that automatically compile, format, and distribute PDF/CSV summaries on a recurring schedule.


1. Administrative Audit Logs & Policy Change Tracking

Compliance frameworks (such as SOC 2 Type II, ISO 27001, PCI-DSS, and HIPAA) mandate a tamper-proof audit trail of all configuration changes made to enterprise security infrastructure. Zscaler Audit Logs record every administrative interaction across the management console.

+-----------------------------------------------------------------------------+
|                        ANATOMY OF AN AUDIT LOG RECORD                       |
+-----------------------------------------------------------------------------+

  [Timestamp]       : 2026-08-27 14:32:10 UTC
  [Admin User]      : sarah.connor@enterprise.com (Role: Super Admin)
  [Source IP]       : 198.51.100.42 (Location: Dallas HQ Jumpbox)
  [Interface]       : ZIA Web Admin Portal (GUI)
  [Action]          : UPDATE / ACTIVATE
  [Category]        : Policy Management
  [Subcategory]     : URL Filtering Rules
  [Resource Name]   : "Block-Unauthorized-Generative-AI"
  [Change Details]  :
      - Pre-Change  : Categories = [Generative AI], Action = CAUTION
      + Post-Change : Categories = [Generative AI], Action = BLOCK, Alert = ON

Core Metadata Captured by Audit Logs:

  • Timestamp: Exact coordinated universal time (UTC) of the administrative event.
  • Administrator Identity: The authenticated username or SAML NameID of the administrator.
  • Client Source IP & Geo: The public IP address and geographic location from which the admin console was accessed.
  • Action Type: CREATE, UPDATE, DELETE, ACTIVATE, LOGIN, LOGOUT, EXPORT, or PASSWORD_CHANGE.
  • Category & Subcategory: The specific platform subsystem (e.g., Administration $\rightarrow$ Admin Users, Policy $\rightarrow$ Cloud App Control, Traffic Forwarding $\rightarrow$ GRE Tunnels).
  • Object Delta (Diff): Granular comparison detailing previous configuration values vs. newly applied parameters.
+-----------------------------------------------------------------------------+
|                TWO-STAGE CONFIGURATION & ACTIVATION WORKFLOW                |
+-----------------------------------------------------------------------------+

  [Admin Editor] ---- 1. Edits URL Rule ----> [Staged Database Draft]
                                                     |
                                        * Audit Log: Action = UPDATE *
                                                     |
  [Admin Approver] -- 2. Reviews Diffs -----> [Verification Engine]
                                                     |
  [Admin Approver] -- 3. Clicks Activate ---> [Global Central Authority]
                                                     |
                                        * Audit Log: Action = ACTIVATE *
                                                     v
                                   [Pushed to 150+ Global Edge Nodes]

[!IMPORTANT] Retention of Audit Logs: In the native Zscaler Admin Portal, administrative Audit Logs are retained for 6 months (180 days). For long-term regulatory compliance (e.g., 7-year retention for financial or healthcare audits), enterprises must stream audit logs to external cold storage or SIEM platforms using the Nanolog Streaming Service (NSS) or Cloud NSS.


2. Interactive Insights Analytics Engines

The Zscaler platform processes hundreds of billions of transactions daily, transforming raw telemetry into interactive, queryable dashboards known as Insights.

+-----------------------------------------------------------------------------+
|                       ZSCALER INSIGHTS ARCHITECTURE                         |
+-----------------------------------------------------------------------------+

                        +-------------------------+
                        |  ZSCALER INSIGHTS CORE  |
                        +-------------------------+
                               /     |     \
                              /      |      \
             +---------------+       |       +---------------+
             |                       |                       |
             v                       v                       v
    +------------------+   +-------------------+   +-------------------+
    | WEB INSIGHTS     |   | FIREWALL INSIGHTS |   | MOBILE INSIGHTS   |
    +------------------+   +-------------------+   +-------------------+
    | * HTTP/S Requests|   | * L3/L4 Sessions  |   | * ZCC OS Platforms|
    | * URL Categories |   | * DNS Queries/Rsp |   | * Mobile Profiles |
    | * Cloud Apps/CASB|   | * Blocked Ports   |   | * Cellular/Wi-Fi  |
    | * DLP Violations |   | * IPS Threat Hits |   | * App Signatures  |
    | * Sandbox Alerts |   | * NAT & Bytes Sent|   | * Jailbreak Alerts|
    +------------------+   +-------------------+   +-------------------+

1. Web Insights (Layer 7 HTTP/HTTPS Analytics)

Web Insights provides deep transaction-level intelligence into all web and SaaS traffic brokered by the ZIA Public Service Edge:

  • Traffic Dimensions: Filter by User, Department, Location, URL Category, Cloud Application, Super Category, Request Method (GET, POST), HTTP Status Code (200, 403, 502), and Device Posture.
  • Security & DLP Drill-Down: Isolate transactions blocked by Advanced Threat Protection (ATP), Malware Protection, Cloud Sandbox (quarantined or weaponized payloads), and inline Data Loss Prevention dictionaries.
  • Data Volumetrics: Quantify inbound bytes, outbound bytes, bandwidth consumption trends, and total transaction counts over selected time ranges (Real-Time 15-mins up to 14 days in interactive views).

2. Firewall Insights (Layer 3/4 & DNS Analytics)

Firewall Insights provides full session telemetry for non-web and web traffic inspected by the ZIA Cloud Firewall and Cloud IPS engines:

  • Session Telemetry: Source IP, Destination IP, Destination Port, Protocol (TCP, UDP, ICMP, GRE), and Network Application signature.
  • DNS Tunneling & Security: Analyzes DNS lookup volumes, blocked malicious domains, Sinkhole responses, and unauthorized DNS resolvers.
  • IPS Rule Hits: Correlates intrusion signatures, CVE numbers, source attack vectors, and automated drop actions.

3. Mobile Insights

Focuses on traffic originating from mobile devices and remote laptops managed via Zscaler Client Connector (ZCC), tracking OS platforms (iOS, Android, Windows, macOS), device hardware IDs, client software versions, and carrier network transitions.


3. ZPA User Activity & Diagnostic Logs

Unlike ZIA (which monitors outbound traffic to the public internet), Zscaler Private Access (ZPA) provides specialized visibility into zero trust access to internal enterprise workloads located in private data centers and clouds (AWS, Azure, GCP).

+-----------------------------------------------------------------------------+
|                        ZPA DIAGNOSTIC LOG FIELDS                            |
+-----------------------------------------------------------------------------+

  1. USER & SESSION CONTEXT
     * Authenticated SAML User (e.g., alex.dev@internal.corp)
     * Client Private IP & Zscaler Client Connector ID
     * Device Posture Token & Compliance Status (Compliant / Non-Compliant)

  2. TARGET APPLICATION CONTEXT
     * Application Segment Name (e.g., "GitLab-Internal-Cluster")
     * Target FQDN / Wildcard Domain (e.g., gitlab.eng.corp.local)
     * Target Port & Protocol (e.g., TCP Port 443 / SSH Port 22)
     * Segment Group & Server Group

  3. BROKERING & HEALTH PATH
     * Public / Private Service Edge Handling Session
     * App Connector Selected (e.g., "AppConn-US-East-01")
     * Target Internal Server IP (e.g., 10.240.12.88)
     * Setup Latency & Connection Status (Active, Closed, Blocked by Policy)
ZPA Diagnostic StatusTechnical CauseTroubleshooting Action
Policy BlockUser does not match any allow rule in Access Policy or posture check failed.Verify SAML group mapping and client device posture attributes.
App Connector UnreachableNo App Connector in the Server Group can reach the internal server IP/port.Test TCP reachability from App Connector host to target backend application.
No Connector AvailableAll App Connectors in the group are offline or disconnected from ZPA cloud.Check App Connector VM status, outbound TLS 443 connectivity, and DNS.
Success / OpenMicro-tunnel successfully stitched between Client and App Connector.Session operating normally at Layer 7.

4. Scheduled Reports & Executive Automation

Enterprise security leaders require recurring executive visibility into threat postures, shadow IT adoption, bandwidth consumption, and compliance enforcement without manually compiling spreadsheet exports.

+-----------------------------------------------------------------------------+
|                        SCHEDULED REPORTING PIPELINE                         |
+-----------------------------------------------------------------------------+

  +-------------------------------------------------------------------------+
  | 1. REPORT TEMPLATE SELECTION                                            |
  |    * Executive Summary Report (C-Level threat & bandwidth trends)       |
  |    * Security & Threat Defense Report (Malware, ATP, Sandbox Hits)      |
  |    * Cloud Application & Shadow IT Adoption (Sanctioned vs Unsanctioned)|
  |    * DLP Compliance & Data Leakage Summary                              |
  +------------------------------------+------------------------------------+
                                       |
                                       v
  +-------------------------------------------------------------------------+
  | 2. SCHEDULE CONFIGURATION                                               |
  |    * Frequency: Daily (06:00 UTC), Weekly (Monday), Monthly (1st)       |
  |    * Time Zone Normalization & Departmental Filtering                   |
  +------------------------------------+------------------------------------+
                                       |
                                       v
  +-------------------------------------------------------------------------+
  | 3. SECURE DISTRIBUTION & NOTIFICATION                                   |
  |    * Format: Password-Protected PDF / CSV Raw Attachment                |
  |    * Delivery: Encrypted Email to CISO, SecOps, & Compliance DLs        |
  +-------------------------------------------------------------------------+

Common Report Types and Target Audiences:

  • Executive Summary Report: Highlights top security risks blocked, high-risk employee browsing behaviors, overall bandwidth consumption, and productivity metrics. Delivered to CIOs and CISOs.
  • Security Analysis Report: Deep technical breakdown of zero-day malware blocked by Cloud Sandbox, top command-and-control (C2) domains sinkholed, and unpatched endpoint vulnerabilities. Delivered to the SOC Lead.
  • DLP Violation Summary: Catalog of sensitive data exfiltration attempts categorized by DLP dictionary (e.g., Credit Card Numbers, HIPAA PHI, Source Code). Delivered to the Compliance and Data Privacy Officer.

5. Exam Tips & High-Yield Distinctions

[!TIP] Audit Logs vs. Insights Telemetry: Always differentiate between Audit Logs and Insights Logs on the exam:

  • Audit Logs: Answer "Who changed what policy in the management portal and when was it activated?" (Administrative plane).
  • Insights Logs: Answer "What websites did user John visit, which files were blocked, and how many bytes were consumed?" (Data plane).

[!IMPORTANT] ZPA Troubleshooting Flow in Diagnostic Logs: When a user reports that an internal application is inaccessible, the primary troubleshooting screen is ZPA Diagnostics $\rightarrow$ User Activity. Look immediately at the Connection Status Code. A status of Policy Block indicates an Access Policy or Posture mismatch, whereas Connection Error or App Connector Unreachable indicates an internal networking, routing, or server-side port reachability failure between the App Connector and the application host.

Loading diagram...
Administrative Audit Logging and Insights Telemetry Pipeline
Test Your Knowledge

A security auditor needs to determine which administrator modified a critical Cloud App Control rule three weeks ago to allow personal cloud storage uploads. Which Zscaler portal feature provides this record?

A
B
C
D
Test Your Knowledge

Which of the following data dimensions is uniquely analyzed within Firewall Insights rather than Web Insights?

A
B
C
D
Test Your Knowledge

An employee attempts to connect to an internal database server via ZPA and receives a connection failure. In ZPA Diagnostics, the administrator observes a connection status of 'App Connector Unreachable'. What is the root cause?

A
B
C
D
Test Your Knowledge

How can an enterprise compliance team receive automated weekly summaries of data loss prevention (DLP) violations and high-risk file downloads without logging into the Zscaler Admin Portal?

A
B
C
D