We've reorganized our documentation navigation structure to align directly with your operational workflows. See the release notes and the walkthrough video for more information.
Stay organized with collections
Save and categorize content based on your preferences.
Change log for ZSCALER_FIREWALL
Date
Changes
2026-05-28
- security_result.detection_fields[fwd_type]: Newly mapped `fwd_type` raw log field with `security_result.detection_fields[fwd_type]` UDM field.
2026-01-07
- Updated the field mapping for the Zscaler Firewall parser.
- Please refer to the parser documentation page for information regarding the updated UDM mappings - https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/zscaler-firewall#udm_mapping_delta
2025-09-26
Improved error handling to cover various edge cases across multiple scenarios.
2025-05-08
- Promoted ZSCALER_FIREWALL Premium parser to default. You can see full details in the parser configuration page - https://cloud.google.com/chronicle/docs/ingestion/default-parsers/ingest-zscaler-logs
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-07-26 UTC."],[],[]]