Monitor Zero Trust Sessions

Connection Events

After a Zero Trust Application Policy is deployed, new fields are available. To add the fields to the table view:

  1. Choose Events & Logs > Analysis > Unified Events.

  2. Click the colum picker (column picker icon) icon and add these columns:

    • Authentication Source

    • Zero Trust Application

    • Zero Trust Application Group

    • Zero Trust Application Host

    • Zero Trust Application Policy

    • Zero Trust Origin User

    • Zero Trust Proxy

    • Zero Trust Rule

    • Zero Trust Status

    • Zero Trust Tunnel ID

  3. Click Apply.

Zero Trust Dashboard

The Zero Trust dashboard allows you to monitor real-time data from active zero trust sessions on the devices.

The Zero Trust dashboard provides a summary of the top zero trust applications and zero trust users that are managed by the management center. Choose Insights & Reports > Dashboard, and click the Zero Trust tab to access the dashboard.

The dashboard has the following widgets:

  • Top Zero Trust Applications

  • Top Zero Trust Users

CLI Commands

Log in to the device CLI and use the following commands:

CLI Command

Description

show running-config zero-trust

To view the running configuration for a zero trust configuration.

show running-config zero-trust-hybrid

To view the running configuration for a universal zero trust configuration.

show zero-trust

To display the run-time zero trust statistics and session information.

show cluster zero-trust

To display the summary of zero trust statistics across nodes in a cluster.

clear zero-trust

To clear zero trust sessions and statistics.

show counters protocol zero_trust

To view the counters that are hit for zero trust flow.