Free tool · CentaurNexus

Analyze your ZCC log bundle - a readable finding instead of ten thousand lines

Drag in the log bundle exported by the Zscaler Client Connector (or pick it manually). You'll get an instant, severity-sorted list of detected failures - tunnel, DNS, PAC file, authentication, posture, SSL, AV/firewall interference - each with a recommendation.

Your logs never leave your machine: unpacking and analysis run entirely in the browser, no data is transferred.

Upload your log bundle

Easiest: drag in the ZIP file exported by ZCC directly. Individual .log/.txt files also work.

Result

Findings

Build and test it here.

Need versioning, four-eyes approval and rollback? CentaurNexus is the sovereign cockpit for your Zscaler world. EU hosting, GDPR-compliant.

View live demo

Frequently asked questions

What does the ZCC Log Analyzer do?

It unpacks the log bundle exported by the Zscaler Client Connector directly in your browser, parses the contained log files (e.g. ZSATunnel, ZSAService, ZSAUpm) and lists detected failure patterns by severity: tunnel connection failures, DNS failures, PAC file errors, authentication loops, posture failures, SSL certificate errors, AV/firewall interference, captive portal detection, and ZCC upgrade problems.

Do my logs leave my machine?

No. Unpacking and analysis run entirely in the browser (JavaScript); there is no server round trip. ZCC logs contain device names, user identifiers and internal hostnames - which is exactly why client-side processing here isn't an option, it's the requirement.

Where do I export the log bundle from the Zscaler Client Connector?

In the ZCC tray icon, use the gear menu "About" or "Advanced" and choose "Export Logs" or "Collect Logs". The Client Connector produces a ZIP archive with all relevant log files, which you drag and drop here.

Do I need Zscaler admin rights to use this tool?

No. The tool only analyzes the ZCC log files that live locally on the endpoint, which any user can export themselves. No access to the Zscaler admin console or OneAPI is required.

CentaurNexus is an independent product of SourcingBlox GmbH and the optimal complement to your Zscaler Security Stack - not an offering from Zscaler, Inc. Product and brand names belong to their respective owners. This tool is a non-binding self-assessment provided without warranty.