> ## Documentation Index
> Fetch the complete documentation index at: https://docs.clarion.cantina.xyz/llms.txt
> Use this file to discover all available pages before exploring further.

# Zscaler

> Receive Zscaler Internet Access security and UEBA alerts as Clarion issues over a per-monitor webhook.

Clarion receives **Zscaler Internet Access (ZIA)** Security and UEBA alerts over a webhook, turning each one into an issue for agent triage.

<Note>
  **Estimated time:** 10 minutes. You will need admin access to the ZIA Admin Portal to configure a webhook destination.
</Note>

## Prerequisites

* A **Zscaler Internet Access** tenant
* Admin rights to configure alert webhooks in the ZIA Admin Portal

## Step 1 — Create the monitor in Clarion

1. In Clarion, open **Integrations** and find **Zscaler**.
2. Click **Connect** and add a monitor.
3. Clarion generates a **webhook URL** and a **shared secret**, shown once.

<Warning>
  The secret is per monitor and stored encrypted. It authenticates the webhook — it travels in the request, never in the URL. Copy it when it is shown.
</Warning>

## Step 2 — Configure the webhook in Zscaler

1. In the **ZIA Admin Portal**, open the alert or webhook configuration for Security and UEBA alerts.
2. Add Clarion's webhook URL as the destination.
3. Configure the shared secret so Clarion can verify each delivery.
4. Send a test alert to confirm delivery.

Clarion rejects deliveries that fail verification, so a misconfigured secret shows up immediately rather than silently dropping alerts.

## What Clarion ingests

ZIA **Security** alerts (policy blocks, malware and threat detections, risky destinations) and **UEBA** alerts (anomalous user behaviour). Each becomes an issue with severity mapped from the Zscaler payload.

## Triaging Zscaler alerts

Zscaler alerts route well to the identity and endpoint skill domains — a UEBA anomaly is usually best pursued through the user's identity provider and their device, both of which Clarion can reach if those integrations are connected.

## Disconnect

Click **Disconnect** on the integration page, and remove the webhook destination from the ZIA Admin Portal.
