Monitor zero trust sessions
This task enables administrators to effectively monitor Zero Trust Application Policy sessions through multiple methods including connection events, dashboard visualization, CLI commands, and diagnostic troubleshooting tools.
After a Zero Trust Application Policy is deployed, additional monitoring capabilities become available to track session activity, user behavior, and system performance. To monitor the zero trust sessions, do these steps.
Procedure
Step 1 | Add Zero Trust fields to the connection events table view.
See Connection and Security-Related Connection Events in the Secure Firewall Management Center Administration Guide for more information on the connection events. | ||||||||||||||
Step 2 | Access the Zero Trust dashboard to monitor real-time session data. The Zero Trust dashboard provides a summary of the top zero trust applications and zero trust users that are managed by the management center. Choose , and click the Zero Trust tab to access the dashboard. The dashboard has the following widgets:
| ||||||||||||||
Step 3 | Use CLI commands to monitor and troubleshoot Zero Trust configurations. Log in to the device CLI and use the following commands:
| ||||||||||||||
Step 4 | Run diagnostic tools to troubleshoot Zero Trust configuration issues. The diagnostics tool facilitates the troubleshooting process by detecting possible issues with zero trust configurations. The diagnostics can be classified into two types:
|
You have successfully configured comprehensive monitoring for Zero Trust sessions. The connection events table now displays Zero Trust-specific fields, the dashboard provides real-time visualization of top applications and users, CLI commands are available for detailed system monitoring, and diagnostic tools can identify and troubleshoot configuration issues.