Feature · Investigation & Diagnostics

Investigation & Diagnostics Answer "what happened?" in under 5 minutes.

When a user says "I can't access this site", the native consoles show data, not answers. ZHERO answers the question directly: will this traffic get through ZIA and ZPA, and if not, which rule stops it. Then it reads the logs that prove it.

Troubleshooting Engine in ZHERO: six scenarios in the rail, each with its answer, and the ZIA verdict Reachable for a user to OneDrive, with where the traffic goes, the result of each engine (Firewall, DNS, SSL Inspection, Cloud App, URL Filtering) and the firewall rules in their real order

75% reduction in Mean Time To Resolution with multi-layer visibility.

Why it matters

One engine for ZIA and ZPA, from verdict to proof

Feature
Reachability verdict
Benefit
Reachable or blocked, per scenario, through every ZIA and ZPA engine in real rule order
Outcome
Start from the answer instead of reconstructing it across 10+ screens
Feature
Log investigation
Benefit
The relevant log reads in sequence, merged into one timeline with diagnosis cards
Outcome
A ticket with a time on it gets a cause, not a log dump
Feature
Floating Logs panel
Benefit
ZIA Web, ZIA Firewall and ZPA logs of any entity, pre-filtered, over the console
Outcome
Check what a rule does right now without leaving the page you are changing
Feature
HAR analysis
Benefit
Protocol per request with an HTTP/3 warning, network errors in plain words, requests handled by Zscaler recognised
Outcome
"The page half works" becomes one named request and one investigation
Feature
ZPA Diagnostics Engine
Benefit
Multi-dimensional drilldown (users, domains, domain:port) with one-click Excel export
Outcome
Raw ZPA diagnostic data becomes actionable intelligence without leaving the console
Feature
Named sessions and history
Benefit
Save and name troubleshooting sessions, investigations and log queries; pin what matters
Outcome
No investigation context lost between shifts

Investigation & Diagnostics removes the investigation tax: when something goes wrong on ZIA or ZPA, the admin normally enters a maze of policy types, diagnostic logs and configuration layers. ZHERO replaces that maze with a guided workflow that goes from a straight answer to the logs that prove it, in minutes.

Reachability verdict

Can this user reach this destination? A straight answer.

Describe the ticket as a scenario (who, from where, to what) and ZHERO says whether the traffic is Reachable or Blocked, naming the engine and the rule that stop it. It follows the traffic through each engine in real rule order, first match wins, for ZIA and ZPA side by side. When the answer depends on a platform, a location or a device group, ZHERO gives an estimate (Probably reachable, It depends, Probably blocked) and shows exactly which evidence it used: on ZIA, the user's own logs or your ZCC fleet. Above the engines, Where the traffic goes shows whether client forwarding sends it to ZIA or to ZPA.

  • Up to 12 scenarios analysed at once, each with its own verdict
  • ZIA and ZPA in the same view, with switched-off rules shown, not skipped
  • Predicted against observed: the verdict is compared with what the logs show
Reachability verdict in ZHERO: Reachable for a user to OneDrive through ZIA, where the traffic goes from Client Connector through Forwarding to ZIA, one tile per engine naming the rule that decides, and the firewall rules in their real order, with the conditions of the conditional rules spelled out

Traffic flow

See where the traffic really goes

The Forwarding tab draws as an interactive Sankey diagram how your configuration routes the traffic: from device groups through forwarding profiles, network state (trusted, off trusted, VPN) and app profiles to ZIA or DIRECT, with the totals above it. Where the forwarding profile sends private apps to ZPA, that branch leaves straight from the network state. It is drawn only from what ZHERO actually read, never guessed; the rules that decide stay in the verdict. Filter it on a user's devices and a misassigned forwarding profile shows up as a path going somewhere you did not expect.

Traffic Flow Analysis in the ZHERO Troubleshooting Engine: an interactive Sankey diagram running from device groups through forwarding profiles, network state and app profiles to ZIA or DIRECT, with the ZPA branch leaving from the network state

Log investigation

From "it failed at about 10:40" to the cause

For a ticket with a time on it, ZHERO runs the relevant log reads one after another (the user's traffic, sub-resources, firewall, ZPA sessions, other users on the same target) and builds one timeline with diagnosis cards that name the likely cause and the next step. The target can be a host or a whole cloud app. When the ticket gives only a day, Only the day draws a heatmap of that day and points to where to look first.

Log investigation in ZHERO: a diagnosis card naming the cause (blocked by cloud application control) with the next step, the note that only one user had failures on the host, and one timeline of web and firewall events with outcome, marks and reason

Floating Logs panel

The logs of any entity, over the console

View Logs on a user, location, department, URL category, cloud app or rule opens ZIA Web, ZIA Firewall and ZPA Diagnostics logs in a movable panel, already filtered on that entity. Keep several panels open while you work in the console, triage with a Policy Action column and filters with value counts, export only the rows you filtered, and keep the queries that matter pinned in History.

The ZHERO Logs panel floating over the Zscaler console, opened from a URL category with View Logs: ZIA Web, ZIA Firewall and ZPA Diagnostics tabs, the filter already set on the category, and the query waiting for Analyze Logs

ZPA Diagnostics Engine

Raw ZPA logs become answers

Multi-dimensional drilldown across users, domains and domain:port combinations, with one-click Excel export running in the background. Raw diagnostic data becomes actionable intelligence without leaving the console, in its own panel or as a tab of the Logs panel.

ZPA diagnostics engine in ZHERO: drilldown from a search to the users, domains and domain and port combinations behind it
How it works

Five investigation steps in one workflow

Step 1

Set criteria

Describe the ticket: user or group, department, location, device group, and the destination URL, category or cloud app. ZHERO turns them into scenarios.

Step 2

Read the verdict

For each scenario, reachable or blocked, and why: the path through each ZIA and ZPA engine, with the rule that decides.

Step 3

Analyze policies and flow

11 policy layers in one view with clear ALLOW and BLOCK indicators, and the forwarding path drawn as an interactive Sankey diagram.

Step 4

Prove it in the logs

Query the real ZIA and ZPA logs for the scenario, or run a guided investigation around the time on the ticket.

Step 5

Save and hand over

Name the session, pin the queries, and let the next engineer resume exactly where you stopped.

Without ZHERO vs With ZHERO

Without ZHERO
With ZHERO
"Can this user reach this site?"
Reconstructed rule by rule across ZIA and ZPA
A verdict per scenario, with the rule that decides
Tracing an access issue
30+ minutes across 10+ screens
Complete traffic flow in a single Sankey diagram
Policy evaluation
One policy type at a time, manually
All 11 policy types evaluated simultaneously
A ticket with a time on it
Web logs, then firewall, then ZPA, lined up by hand
One timeline with diagnosis cards
Logs of a user or a rule
Leave the page, open the log viewer, rebuild the filter
View Logs from the entity, in a panel over the console
ZPA diagnostics
Copy-pasting log data into spreadsheets
One-click drilldown and Excel export, running in the background
FAQ

Questions, answered

Does my traffic data leave the browser?
No. The analysis is 100% browser-based: HAR files never leave your machine and their query strings are never stored, ZHERO uses your existing Zscaler session to read the logs, and no configuration or traffic data is transmitted to ZHERO servers.
Does the Troubleshooting Engine cover ZPA as well as ZIA?
Yes. The same scenario is evaluated through ZIA and ZPA side by side, and on a ZPA-only tenant the ZPA verdict takes the lead. The ZPA Diagnostics Engine adds the population view: every user, domain and port behind a filter.
Is Investigation & Diagnostics fully released?
Yes. The floating Logs panel and the Troubleshooting Engine, with the reachability verdict, the traffic flow, the log investigation and HAR analysis, are released with the full licence and not included in the trial. The ZPA Diagnostics Engine is shipped in Beta and being refined with every release.
Does ZHERO run log queries on its own?
No. Zscaler allows one log query at a time per admin session, so ZHERO pre-fills every query and waits for you to run it, instead of replacing one you already have running.
Can I export the results?
Yes. Any ZPA drilldown result and any log table exports to a professionally formatted Excel file in one click, including just the rows you filtered.

Investigation & Diagnostics in action

Watch a 4-minute demo.

Ready to see Investigation & Diagnostics in your tenant?

Start Your Transformation!

Install in two minutes. No servers, no migration, no training.