
Grafana MarketplaceCommercial Plugin
Zscaler ZIA Plugin for Grafana
Monitor Internet Access Policies in Grafana
Built for
9
ZIA data categories
0
Agents or exporters required
OAuth 2.0
Secure authentication
≥ 12.3
Grafana version supported
Overview
Monitor ZIA in Grafana
Official Zscaler Go SDK
OAuth 2.0 via ZIdentity
Nine ZIA data categories
Single pane of glass
The Zscaler ZIA plugin is a backend data source plugin that enables on-demand querying and visualization of Zscaler Internet Access (ZIA) security posture data inside Grafana panels, using the official Zscaler Go SDK. Security and platform teams get policy and configuration visibility in the same dashboards they already use for the rest of their stack.
Zscaler Internet Access is a cloud-native security service edge (SSE) platform that enforces internet access policies, inspects traffic, and protects users from threats regardless of location. The plugin connects to the ZIA API to retrieve organization health, firewall filtering rules, SSL inspection policies, URL filtering rules, data loss prevention rules, location infrastructure, user management data, NSS server health, and sandbox detonation quota, so teams can audit posture, review policy changes, and track configuration drift from a single pane of glass.
Coverage
What You Can Monitor
The plugin exposes nine ZIA data categories, selectable by query type in the query editor, spanning policy, identity, and infrastructure.
01 — Policy
Security Policies
Firewall Rules (order, rank, action, state, source/destination IP counts), SSL Inspection (TLS constraints, HTTP/2, URL-category and cloud-app counts), URL Filtering (categories, protocols, block override, time/size quotas), and web DLP Rules (severity, OCR, download scan, ZCC notification, audit) — a complete view of enforcement posture.
firewall.rulesssl.inspectionurl.filteringdlp.rules
02 — Identity
Locations & Users
Location Infrastructure (bandwidth, SSL scan, firewall, VPN, IPS, IPv6 — with a Locations Lite mode for fast security-flag review) and User Management records (department, group count, admin status, account type) for identity and access visibility.
location.bandwidthlocation.vpnuser.departmentuser.type
03 — Control Plane
Infrastructure & Sandbox
Organization Health metadata (org ID, cloud, domain count, HQ, industry, employee count, ZPA tenant), NSS Server Health across log-stream server types, and Sandbox Quota (usage, limit, remaining, utilization %), so teams keep the ZIA control plane healthy and within limits.
org.healthnss.serversandbox.quotasandbox.used
See It in Grafana
Set up and query, right inside Grafana
Connect the data source with OAuth 2.0 via the Zscaler ZIdentity portal, then build posture queries across nine data categories in a guided editor.
1 / 2

01
Data Source Configuration
Connect with OAuth 2.0 through the ZIdentity portal using scope-based access, then Save & test.

02
Query Editor
Pick a query type across the nine ZIA categories, then filter by ID, name, action, order, location, or time range.
Differentiators
Why Crest Data's Zscaler ZIA Plugin?
Native & Agentless
Talks directly to the ZIA API through the official Zscaler Go SDK with OAuth 2.0 from the Go backend. No agents, no exporters, no extra collection layer to deploy or maintain.
Nine Data Categories
Query Organization Health, Location Infrastructure, Firewall Rules, SSL Inspection, URL Filtering, DLP Rules, User Management, NSS Server Health, and Sandbox Quota for complete security-posture visibility.
Granular Filtering
Combine server-side and client-side filtering, look up rules and locations by ID or exact name, and narrow firewall rules by action, order, location, and department for precise, targeted queries.
Time-Aware Policy Review
An optional time filter restricts rules and sandbox quota to items modified within the dashboard time range, making it easy to review recent policy changes and configuration drift.
Official SDK & OAuth 2.0
Built on the Zscaler Go SDK v3 with OAuth 2.0 authentication via the ZIdentity portal and scope-based access, aligning with Zscaler's current, recommended integration path.
Resilient by Design
Automatic rate-limit retry with backoff through the Zscaler SDK (up to 3 attempts), with clear, descriptive errors for authentication and missing-scope conditions.
Built and Maintained by Crest Data
Developed and proactively maintained by Crest Data as a commercial Grafana Marketplace plugin, with continuous compatibility as the Zscaler API and SDK evolve.
How to Get the Plugin
Zscaler ZIA is a commercial plugin on the Grafana Plugin Marketplace
To license it or set up an evaluation, contact the Grafana Marketplace team.
Grafana Marketplace
plugins-marketplace@grafana.com
Plugin ID
crestdata-zscalerzia-datasource
Get the Plugin Now


