Skip to content

[zscaler_zia] Add support for Email DLP data stream - #18981

Merged
brijesh-elastic merged 7 commits into
elastic:mainfrom
brijesh-elastic:zscaler_zia-email_dlp
Jun 18, 2026
Merged

[zscaler_zia] Add support for Email DLP data stream#18981
brijesh-elastic merged 7 commits into
elastic:mainfrom
brijesh-elastic:zscaler_zia-email_dlp

Conversation

@brijesh-elastic

Copy link
Copy Markdown
Contributor

Proposed commit message

zscaler_zia: Add support for Email DLP data stream.

This data stream collects Email DLP logs[1] using Zscaler ZIA
Nanolog Streaming Service (NSS).

Test samples were derived from documentation and live data samples, 
which were subsequently sanitized.

[1] https://help.zscaler.com/zia/nss-feed-output-format-email-dlp-logs

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

How to test this PR locally

  • Clone integrations repo.
  • Install elastic package locally.
  • Start elastic stack using elastic-package.
  • Move to integrations/packages/zscaler_zia directory.
  • Run the following command to run tests.

elastic-package test -v

@brijesh-elastic brijesh-elastic self-assigned this May 13, 2026
@brijesh-elastic brijesh-elastic added documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. enhancement New feature or request Integration:zscaler_zia Zscaler Internet Access Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] Team:SDE-Crest Crest developers on the Security Integrations team [elastic/sit-crest-contractors] labels May 13, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Vale Linting Results

Summary: 12 warnings found

⚠️ Warnings (12)
File Line Rule Message
packages/zscaler_zia/docs/README.md 981 Elastic.Latinisms Latin terms and abbreviations are a common source of confusion. Use 'and so on' instead of 'etc'.
packages/zscaler_zia/docs/README.md 981 Elastic.DirectionalLanguage Don't use directional language. Use 'earlier on this page' instead of 'noted above'.
packages/zscaler_zia/docs/README.md 982 Elastic.DirectionalLanguage Don't use directional language. Use 'earlier on this page' instead of 'noted above'.
packages/zscaler_zia/docs/README.md 983 Elastic.QuotesPunctuation Place punctuation inside closing quotation marks.
packages/zscaler_zia/docs/README.md 984 Elastic.Latinisms Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'.
packages/zscaler_zia/docs/README.md 985 Elastic.Latinisms Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'.
packages/zscaler_zia/docs/README.md 989 Elastic.Latinisms Latin terms and abbreviations are a common source of confusion. Use 'that is' instead of 'i.e'.
packages/zscaler_zia/docs/README.md 1018 Elastic.Latinisms Latin terms and abbreviations are a common source of confusion. Use 'that is' instead of 'i.e'.
packages/zscaler_zia/docs/README.md 1019 Elastic.Latinisms Latin terms and abbreviations are a common source of confusion. Use 'that is' instead of 'i.e'.
packages/zscaler_zia/docs/README.md 1024 Elastic.Latinisms Latin terms and abbreviations are a common source of confusion. Use 'that is' instead of 'i.e'.
packages/zscaler_zia/docs/README.md 1024 Elastic.Latinisms Latin terms and abbreviations are a common source of confusion. Use 'that is' instead of 'i.e'.
packages/zscaler_zia/docs/README.md 1027 Elastic.Latinisms Latin terms and abbreviations are a common source of confusion. Use 'that is' instead of 'i.e'.

The Vale linter checks documentation changes against the Elastic Docs style guide.

To use Vale locally or report issues, refer to Elastic style guide for Vale.

@elastic-vault-github-plugin-prod

elastic-vault-github-plugin-prod Bot commented May 13, 2026

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

Package zscaler_zia 👍(6) 💚(3) 💔(2)

Expand to view
Data stream Previous EPS New EPS Diff (%) Result
alerts 3623.19 2475.25 -1147.94 (-31.68%) 💔
saas_security 2840.91 2347.42 -493.49 (-17.37%) 💔

To see the full report comment with /test benchmark fullreport

@botelastic

botelastic Bot commented Jun 12, 2026

Copy link
Copy Markdown

Hi! We just realized that we haven't looked into this PR in a while. We're sorry! We're labeling this issue as Stale to make it hit our filters and make sure we get back to it as soon as possible. In the meantime, it'd be extremely helpful if you could take a look at it as well and confirm its relevance. A simple comment with a nice emoji will be enough :+1. Thank you for your contribution!

@botelastic botelastic Bot added the Stalled label Jun 12, 2026
@botelastic botelastic Bot removed the Stalled label Jun 17, 2026
@brijesh-elastic
brijesh-elastic marked this pull request as ready for review June 17, 2026 11:53
@brijesh-elastic
brijesh-elastic requested review from a team as code owners June 17, 2026 11:53
@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@brijesh-elastic brijesh-elastic added the dashboard Relates to a Kibana dashboard bug, enhancement, or modification. label Jun 17, 2026
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

✅ All changelog entries have the correct PR link.

@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

History

cc @brijesh-elastic

@brijesh-elastic
brijesh-elastic merged commit fdbcb9d into elastic:main Jun 18, 2026
12 checks passed
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package zscaler_zia - 4.1.0 containing this change is available at https://epr.elastic.co/package/zscaler_zia/4.1.0/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dashboard Relates to a Kibana dashboard bug, enhancement, or modification. documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. enhancement New feature or request Integration:zscaler_zia Zscaler Internet Access Team:SDE-Crest Crest developers on the Security Integrations team [elastic/sit-crest-contractors] Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

3 participants