Zscaler proxies the web session itself, so its logs carry full URLs and authenticated usernames. For shadow AI, that is the richest evidence any log source produces. Here is how to spend it.
DNS logs prove a tool was reached. Proxy logs add who, how often, and how much moved. Both feed the same audit; Zscaler simply feeds it more.
Privacy note: the audit only uses the hostname and the identity. Paths, query strings and payload sizes never influence a verdict and never appear in the report, and the uploaded file is discarded after the run.
A 600-person software company, Zscaler in front of everything. Sample data, familiar outcome: the tools were not the ones IT had approved.
Platform team pulls 30 days of web logs filtered to allowed traffic: 380,000 transactions, 5.1 MB compressed to CSV essentials. Full-report territory, uploaded in one go.
44 AI tools surface. The approved list has 6. Code & Development alone shows 9 distinct assistants across engineering.
Three unsanctioned code assistants carry heavy per-user traffic in the platform group, one of them with an opt-out training default nobody had flipped. Proprietary code has plausibly been pasted into consumer tiers for months.
An agent-builder platform appears with API-shaped traffic from a build server's service account. Someone wired an LLM into CI without a review. The per-user table caught it because Zscaler logged the service identity.
One assistant gets sanctioned on an enterprise no-training tier for everyone. The other two get blocked, and the CI integration gets a design review instead of a burial. The audit PDF is the artifact in all three tickets.
Same window, next month: blocked assistants show attempts only, sanctioned share up from 14% to 61%. That delta is the slide leadership sees.
You want the web transaction log as CSV over your window. Conceptually it is the web log view in analytics; exact naming varies by console generation, and any CSV with a header row parses.
Highlighted hosts match the register. Note the service account on line three: proxy identity catches non-human AI usage too.
Zscaler deployments differ in how much they decrypt. All three configurations still feed a valid audit.
Every transaction logged with full URLs. Hit counts track real usage closely, and API subdomains show up distinctly.
Uninspected sessions still log the hostname from SNI. You lose URL depth, which the audit does not need anyway.
Traffic in bypass lists may skip web logging entirely. Cross-check with a DNS export once a year; the methodology page covers multi-source audits.
Proxy evidence lights up every section of the report, including the ones DNS sources leave thin.
| Report section | With a Zscaler CSV |
|---|---|
| Summary tiles | Full totals with risk, training and abusive-purpose counts. |
| Tool table | Every matched tool; hit counts reflect real transactions, not cached DNS. |
| Per-user breakdown | Authenticated usernames per tool, including service accounts. The strongest accountability any source offers. |
| Sanctioned split | Approved list vs observed, per tool and per user. |
| Policy verdicts | Block / control / allow suggestions per tool under your chosen profile. |
| CSV + PDF | Both ship with the full report, ready for the risk register and the board pack. |
The export is read once, matched in memory and discarded. Reports are stored 90 days in your account and deletable earlier.
Engineering networks produce distinctive shadow AI signatures. These are the ones worth a second look.
The sample evidence pack shows every section a Zscaler export fills: tiles, verdicts, the per-user table with a service account in it.
The report's three verdict groups map onto three pieces of configuration work, then one verification run.
Monthly re-runs are what plan allowances are for; packs work for one-off engagements. Both are on the pricing page, and the free tier detail is on the free audit page.
Zscaler's transaction counts are the most honest of any source, but three effects still distort them.
A chat tool polling every few seconds racks up transactions while idle. Compare tools by user count first, hits second.
Tools serving their app from a generic CDN log fewer transactions on their own domain. The auth and API hostnames still give them away.
A single heavy user can put a niche tool near the top by hits. The per-user column keeps the ranking honest.
Rule of thumb for proxy reports: rank by users for policy decisions, rank by hits for capacity and procurement conversations.
Proxy logs are bulkier than DNS. Column discipline matters more here than anywhere else.
| Org size | A month of web log, trimmed to 4 columns | Recommended path |
|---|---|---|
| Under 100 users | Tens of thousands of lines, a few MB | Full report directly; a filtered week fits the free preview. |
| 100 to 1,000 | Hundreds of thousands of lines | Full report, filter to allowed traffic, drop byte columns. |
| 1,000 to 5,000 | Millions of transactions | Two-week window, or sample one representative week per month. |
| 5,000+ | Beyond single-file caps | Ask us: larger exports are handled on request as a custom run. |
The audit crosses three desks. Knowing the handoffs beforehand keeps it a one-week exercise.
Owns the export: window, columns, filter to allowed. Fifteen minutes of console work, and later owns the URL-category changes the verdicts call for.
Runs the upload, reads the report, drafts the sanction/control/block split. Presents the tiles to leadership with the annotated tour as a reading guide.
Owns the conversations the per-user table starts, especially assistant consolidation and the CI integrations that deserve review rather than blocking.
The web transaction log as CSV with time, user and URL or host columns. Any header-row CSV parses automatically.
Paths are stripped to hostnames at parse time, never matched, never shown in the report, and the upload is discarded after the run. Exporting a host-only column is equally fine.
Bypassed traffic misses web logs, yes. Run a DNS-source audit occasionally as a cross-check; the Umbrella guide covers that shape.
Developer-heavy orgs generate a lot of transactions. Filter to allowed traffic and drop unneeded columns; the full report takes 2,000,000 lines or 25 MB, larger on request.
Yes. Proxied API calls carry hostnames and the authenticated service identity, which is how CI-embedded AI gets caught.
No, it feeds them. The report tells you which tools to put into which rule, with dated training verdicts your change ticket can cite.
Zscaler deployments often carry both internet security and private access. Only one of them matters here.
Multi-source truth: proxy logs for depth, DNS logs for breadth, one audit each, compared side by side. Teams running both catch bypass gaps the same week they appear. Start with whichever export is one click away today.
Export a window, upload it, read the totals free. The per-user table is where engineering orgs find their surprises.
Run the free audit