ZPA Logging, Monitoring & Troubleshooting

Zscaler Private Access (ZPA) Zscaler portal — demo tenant (GUI)

مقصدObjectiveObjective

اس سبق میں آپ ZPA logs پڑھیں گے، connector health monitor کریں گے، اور سب سے عام ZPA مسائل کو ترتیب سے حل کریں گے۔Is lesson mein aap ZPA logs parhenge, connector health monitor karenge, aur sab se aam ZPA masail ko tarteeb se hal karenge.In this lesson you will read ZPA logs, monitor connector health, and troubleshoot the most common ZPA issues in order.

آسان مثالSimple AnalogySimple Analogy

ZPA logs ایسے ہیں جیسے ہر مہمان کا CCTV ریکارڈ: کون آیا، کس کمرے میں گیا، کس وقت، اور کس کو دروازے پر روکا گیا۔ZPA logs aise hain jaise har mehman ka CCTV record: kaun aaya, kis kamre mein gaya, kis waqt, aur kis ko darwaze par roka gaya.ZPA logs are like a CCTV record of every guest: who came, which room they went to, what time, and who was stopped at the door.

سیٹ اپLab SetupLab Setup

Zscaler پورٹل ڈیمو ٹیننٹ۔ Analytics > Logs اور Administration > App Connectors کھولیں۔ Client device پر ZPA module کے ساتھ Zscaler Client Connector چل رہا ہے۔Zscaler portal demo tenant. Analytics > Logs aur Administration > App Connectors kholein. Client device par ZPA module ke saath Zscaler Client Connector chal raha hai.Zscaler portal demo tenant. Open Analytics > Logs and Administration > App Connectors. The client device runs Zscaler Client Connector with the ZPA module.

اقداماتStepsSteps

Step 1

Analytics > Logs پر جائیں۔ ہر ZPA session log ہوتی ہے: user, device, segment, policy decision، اور کون سے App Connector نے serve کیا۔Analytics > Logs par jayein. Har ZPA session log hoti hai: user, device, segment, policy decision, aur kaun se App Connector ne serve kiya.Go to Analytics > Logs. Every ZPA session is logged: user, device, segment, policy decision, and which App Connector served it.

🖱️ Analytics > LogsAnalytics > LogsAnalytics > Logs

Step 2

Logs کو user اور time سے filter کریں۔ Denied sessions میں واضح لکھا ہوتا ہے کہ کس policy rule نے block کیا — یہ سب سے تیز سراغ ہے۔Logs ko user aur time se filter karein. Denied sessions mein wazeh likha hota hai ke kis policy rule ne block kiya — ye sab se tez suraagh hai.Filter the logs by user and by time. Denied sessions show the exact policy rule that blocked them — your fastest clue.

Step 3

Administration > App Connectors میں health دیکھیں: CPU, memory, tunnel status۔ بیمار connector ایپس کو unreachable یا slow بنا دیتا ہے۔Administration > App Connectors mein health dekhein: CPU, memory, tunnel status. Bemar connector apps ko unreachable ya slow bana deta hai.Check Administration > App Connectors for health: CPU, memory, and tunnel status. An unhealthy connector makes apps unreachable or slow.

🖱️ Administration > App ConnectorsAdministration > App ConnectorsAdministration > App Connectors

Step 4

Client پر Client Connector کے diagnostics (About / Diagnostics) سے sign-in state اور ZPA service reachability چیک کریں۔Client par Client Connector ke diagnostics (About / Diagnostics) se sign-in state aur ZPA service reachability check karein.On the client, use the Client Connector's diagnostics (About / Diagnostics) to check sign-in state and ZPA service reachability.

Step 5

Troubleshooting کی ترتیب follow کریں: client (sign-in, module on) → policy (کون سا rule لگا) → segment (FQDN/port صحیح) → connector (healthy)۔Troubleshooting ki tarteeb follow karein: client (sign-in, module on) → policy (kaun sa rule laga) → segment (FQDN/port sahi) → connector (healthy).Follow the troubleshooting order: client (sign-in, module on) → policy (rule matched) → segment (FQDN/port correct) → connector (healthy).

Step 6

Slow app کی عام وجہ: قریبی connector down ہے اور ٹریفک دور والے سے گزرتی ہے۔ حل: group میں ایک اور connector لگائیں۔Slow app ki aam wajah: qareebi connector down hai aur traffic door wale se guzarta hai. Hal: group mein ek aur connector lagayein.Common slow-app cause: the nearest connector is down and traffic detours through a far one. Fix: add another connector to the group.

تصدیقVerifyVerify

Test user کے پچھلے گھنٹے کے logs نکالیں اور ہر entry سمجھائیں: کس rule نے allow کیا، کس connector نے serve کیا، session کتنی لمبی تھی۔Test user ke pichle ghante ke logs nikalein aur har entry samjhayein: kis rule ne allow kiya, kis connector ne serve kiya, session kitni lambi thi.Pull the last hour of logs for your test user and explain each entry: which rule allowed, which connector served, and session length.

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ Segment اور policy صحیح ہونے کے بعد بھی app unreachable ہے۔Segment aur policy sahi hone ke baad bhi app unreachable hai.App unreachable even though the segment and policy are correct.

✅ Administration > App Connectors چیک کریں — group کے سارے connectors offline ہو سکتے ہیں۔ یہ بھی تصدیق کریں کہ connector VM خود ایپ تک پہنچ سکتا ہے۔Administration > App Connectors check karein — group ke sare connectors offline ho sakte hain. Ye bhi confirm karein ke connector VM khud app tak pahunch sakta hai.Check Administration > App Connectors — the group's connectors may all be offline. Also confirm the connector VM can reach the app itself.

⚠️ Client Connector میں ZPA disabled نظر آ رہا ہے۔Client Connector mein ZPA disabled nazar aa raha hai.Client Connector shows ZPA disabled.

✅ ZPA module پورٹل کے client forwarding profile سے control ہوتا ہے۔ پورٹل کی Client Connector policy چیک کریں اور client کو دوبارہ enroll کریں۔ZPA module portal ke client forwarding profile se control hota hai. Portal ki Client Connector policy check karein aur client ko dobara enroll karein.The ZPA module is controlled by the client forwarding profile in the portal. Check the portal's Client Connector policy and re-enroll the client.

⚠️ Access کبھی لگتا ہے کبھی نہیں — intermittent مسئلہ۔Access kabhi lagta hai kabhi nahi — intermittent masla.Intermittent access — sometimes works, sometimes denied.

✅ عموماً posture check اٹک رہا ہے (جیسے AV signature updates)۔ Analytics > Logs میں device سے filter کر کے posture results دیکھیں۔Amuman posture check atak raha hai (jaise AV signature updates). Analytics > Logs mein device se filter kar ke posture results dekhein.Likely a posture check flapping (e.g. AV signature updates). Filter Analytics > Logs by device and check posture results across sessions.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ User کہتا ہے ایپ slow ہے — سب سے پہلے کہاں دیکھیں گے؟User kehta hai app slow hai — sab se pehle kahan dekhenge?A user says the app is slow — where do you look first?

Analytics > Logs کھولیں، user, segment یا time سے filter کریں، اور policy decision، استعمال ہوا connector اور session times دیکھیں۔Analytics > Logs kholein, user, segment ya time se filter karein, aur policy decision, istemal hua connector aur session times dekhein.Open Analytics > Logs, filter by user, segment, or time, and look at the policy decision, connector used, and session times.

❓ User کسی ایپ تک نہیں پہنچ سکتا — troubleshooting order کیا ہو گی؟User kisi app tak nahi pahunch sakta — troubleshooting order kya hogi?A user cannot reach any app — what is your troubleshooting order?

پہلے Client Connector کا sign-in، پھر segment definition، پھر policy، پھر connector health — client سے cloud سے connector تک۔Pehle Client Connector ka sign-in, phir segment definition, phir policy, phir connector health — client se cloud se connector tak.Check Client Connector sign-in state, then the segment definition, then the policy, then connector health — client to cloud to connector.