What is ZDX Deep Tracing?
ZDX Deep Tracing is a detailed diagnostics function in Zscaler Digital Experience (ZDX) that captures in-depth telemetry for a single user or device over a limited time window. While ongoing monitoring measures and aggregates at regular intervals, a Deep Tracing session gathers close-interval data on device, network path and application to work through an active problem in detail. Administrators start the session in ZDX, and data collection runs through the Zscaler Client Connector on the endpoint. Deep Tracing is the tool for the second stage of troubleshooting: the ZDX score shows that something is off, Deep Tracing helps pin down where.
ZDX Deep Tracing in detail
A Deep Tracing session starts for one specific user and device, optionally narrowed to a monitored application, and runs for between 5 and 60 minutes depending on what you choose. It requires an active measurement to have been running on the device for at least 30 minutes already. During the session, the client collects much finer measurement series than in normal operation: web and network path readings every minute instead of the regular interval, plus device statistics and, optionally, a packet capture (PCAP). You can export the result as a PDF and share it.
What matters is its character as a snapshot: a Deep Tracing session observes only the period while it runs. That makes it well suited to active or reproducible problems (“it's stuttering right now”, “the call freezes every hour”), less so to one-off issues that faded away long ago. In practice, you combine it with the historical view from regular monitoring. The trend shows when things were bad, Deep Tracing supplies the depth for the current state.
Why ZDX Deep Tracing matters in Zscaler operations
In operations, ZDX Deep Tracing closes the gap between “the score is bad” and “the cause is named”. A classic case: a key user reports recurring drop-outs in video calls, while standard monitoring shows only intermittent anomalies. A targeted trace during the problem reveals whether the workplace Wi-Fi, the provider segment, an overloaded endpoint, or a segment behind the Zscaler cloud is costing the time.
Organisationally, it needs settling who is allowed to start a Deep Tracing session. In many environments, the ZDX portal sits with the network or security team, while cases land at the helpdesk first. That is exactly the handoff gap that stretches tickets out: 1st Level support gathers symptoms, the expert then repeats the diagnosis. The earlier trace findings land in the ticket in structured form, the less often measurement gets duplicated and cases get escalated.
Common sources of error
- Started too late: a ZDX Deep Tracing session only observes the current time window; it yields little for a problem that has already faded.
- Wrong scope: failing to narrow down user, device or application cleanly produces data noise instead of a solid diagnosis.
- Results without a baseline: anomalous readings need a reference, for example the same user at a good time, or colleagues at the same site.
- Findings go nowhere: if the result never gets documented in the ticket, the next person repeats the entire diagnosis.
ZDX Deep Tracing in practice: what CentaurNexus contributes
CentaurNexus steps in ahead of detailed diagnostics. Connectivity Triage Map pulls together the ZDX chain and the policy status and names the cause in plain language, whether that's the ISP, Wi-Fi, device or Zscaler. That lets the helpdesk clear the standard cases without anyone opening a ZDX portal, and escalates only the cases that genuinely need deeper analysis to the expert team, already carrying a preliminary finding. User Support Center adds the 360-degree user view across ZIA, ZPA and ZDX in one screen, with no Zscaler admin rights needed. For how this division of labour shortens tickets, see the guide Is it Zscaler or the Wi-Fi?.
Related terms
Frequently asked questions about ZDX Deep Tracing
ZDX Deep Tracing makes sense for active or reproducible problems affecting a single user or device, for example recurring drop-outs in video calls. It observes only the current time window; for one-off issues that faded long ago, the historical view from regular ZDX monitoring on trend data is the better fit.
The score is an aggregated value that shows something is off. ZDX Deep Tracing supplies the depth behind it: close-interval measurements of device state, network path and application behaviour while the problem is happening. That lets you narrow down which segment of the chain is costing the time.
You set the duration when you start the session, and it is capped; the ZDX documentation describes the available options. What matters is timing the trace so the problem actually occurs while it runs, otherwise the session just documents an uneventful period. For sporadic faults, it helps if users report the moment it happens right away.
The already-installed Zscaler Client Connector collects the data; there is no remote access to the screen or files. What gets captured is technical telemetry about the device, the network and the monitored applications. The device needs to be online for this and running a ZDX-capable client version.
You start it from the ZDX portal, which requires an appropriate administrator or analyst role; Zscaler administration defines those roles and permissions. In practice, access often sits with network or security teams, which is why helpdesk processes should define when to escalate and with what preliminary findings.
- Zscaler Help Portal: ZDX documentation, help.zscaler.com/zdx
- Zscaler Help Portal: About Diagnostics (Deep Tracing) - help.zscaler.com/zdx/about-deep-tracing
Note: ZDX Deep Tracing is a feature of Zscaler ZDX; CentaurNexus starts it with one click and makes the finding easy to read. CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.