Hey everyone,
I've been evaluating ZPA for our team's zero-trust access needs, and the overall concept seems solid. However, I'm hitting a bit of a wall with something specific for our upcoming security audit.
Our compliance team is asking for detailed logs of user access to internal applications. They want to see who connected to what, when, and ideally the amount of data transferred (or at least connection details). I know ZPA has the Admin Portal and reporting, but I'm struggling to find if the granular, per-user traffic data I need is readily available.
From my poking around, I see session logs and audit logs, but they seem more focused on administrative changes or high-level connection events. Can anyone clarify:
1. Does ZPA actually log detailed network traffic data (like bytes in/out per session) for individual users accessing an application segment?
2. If this data exists, what's the best way to extract it? Is it through the ZPA Admin Portal's reporting, or do I need to use APIs to pull it from the cloud service? I'm not a full-time admin, so the API route seems a bit daunting.
3. How far back does this kind of data typically go? Our audits sometimes require looking at data from 3-6 months prior.
I'm trying to build a complete picture before we commit, and this logging capability is a major point for our security review. Any insights or experiences you can share would be super helpful!