Skip to content

Export Catalog

ZHERO produces nine Excel reports the Zscaler console does not, all through the same drawer: you choose the columns, their order, how multi-value fields are laid out, and whether your team’s tags and comments come along.

This page is the index of what you can export and how the drawer works. The URL export has its own page, because it is the largest.

When to use it

  • Handing data to another team: the firewall team, the auditors, the endpoint team. They do not have ZHERO and should not need it.
  • Recurring reviews: save the column set once and produce the identical sheet next month.
  • Cleanup by numbers: rules and categories with zero traffic over 30 days are a list, and a list is easier to act on than a console screen.
  • Migration inventories: segments, domains, ports and connector groups in one sheet.

Where to find it in the UI

Hover the ZHERO icon, then open the Exports button (download icon). The menu groups the entries under Export - Common, Export - ZIA and Export - ZPA, and lists the ones available for your tenant type. Each opens the same drawer, titled “Export (report name)”.

The ZHERO export menu open in the console, grouped into Export - Common, Export - ZIA and Export - ZPA, with the Diagnostics entry marked BETA at the bottom

The last entry, Diagnostics (BETA), is not an export: it opens the ZPA diagnostics engine, which shares the menu because it shares the drawer.

The nine exports

ExportWhat it carries
URL InventoryEvery URL across categories, rules, PAC files and profiles, with wildcard detection, policy impact, category membership, security-risk classification and zero-impact highlighting
Firewall RulesFull rule configuration (source, destination, action, protocols) with 30-day traffic volume and transaction count per rule, disabled rules greyed and block actions highlighted
Location ConfigurationEvery location and sub-location, its settings, policy usage count, and both web and firewall traffic for the last 30 days with share percentages
App & Forwarding ProfilesThe ZCC profile inventory with configuration per profile, PAC file content, usage indicators, and the policy-token and machine-token columns
SSL Inspection PolicyRule configuration, inspect against bypass action, protocol settings, 30-day traffic, and which traffic bypasses inspection
URL Filtering PolicySource criteria, destination categories, action, scheduling, protocol and port detail, with 30-day traffic per rule
Cloud App Control RulesCloud app names, categories and risk classification per rule, the granular operation controls (upload, download, share), user and group criteria, and 30-day usage
ZPA Access PolicyPolicies in flat mode (one row per policy) or expanded mode (one row per condition), with full attributes and application references
ZPA Application SegmentSegments with domains, FQDNs, IP and CIDR ranges, TCP and UDP port ranges with service names, server and connector groups, and the access policies that reference each one

An exported firewall rules workbook in Excel, produced by ZHERO, with rule name, action, state, labels and the last 30 days of traffic per rule, formatted and colour-coded

The export drawer

Every export shares the same controls.

Columns

Columns are grouped by theme and selected with checkboxes. Hover a column name for a description of what it contains. Below the selection, the chosen columns appear as a draggable list: the order there is the column order in the Excel sheet.

Flat or matrix, for multi-value fields

A field that holds several values (the user groups on a rule, the categories on a policy) can be exported two ways:

ModeResultUse it for
FlatAll values in one cell, joined by a separatorReading, printing, sharing
MatrixOne column per distinct valueFiltering and pivoting in Excel

Matrix columns are marked as such in the reorder list, and they move as a single item.

Separator

For flat multi-value cells, choose comma, semicolon or newline. Newline is the one that survives a paste into most other tools.

Collaboration columns

Where Collaboration is enabled, the export can include your team’s tags, preferred tags and comments next to the configuration data. An audit spreadsheet where each rule already carries its review status, in the team’s own words, does not need a second tracking sheet.

Templates

Each export keeps two preset slots. Save your current column selection, modes and separator into a slot, then load it with one click next time. Reset returns the drawer to its defaults.

Generating

Press the export button and the drawer shows progress while the workbook is built, then downloads it. Large tenants take longer: the work is the data gathering, not the file.

What to watch

  • The traffic window is 30 days wherever traffic columns appear, and it is the same window Zscaler exposes. For the 180-day view, see Traffic Analytics; the two windows are mutually exclusive within a sheet, so a report always states which one it reflects.
  • Zero traffic is not the same as unused. Check a longer window before deleting on the strength of a 30-day zero.
  • Flat mode for humans, matrix mode for Excel. Choosing matrix because it looks complete usually produces a sheet nobody can read.
  • Column order matters more than it seems when the sheet goes to someone outside the team. Put the identifying columns first.

Limits and notes

  • Exports are read-only. Nothing here changes the tenant.
  • Advanced export options and templates require the full version. During a trial the drawer opens and the controls are visible, with an upgrade prompt in place of the download.
  • Available exports depend on the tenant type. ZPA exports appear on ZPA-capable tenants, ZCC profile exports where the data exists.
  • Your Zscaler role bounds the content. Objects your role cannot read are not in the sheet.
  • Two template slots per export, per tenant. They are yours, not the team’s.

FAQ

Can I schedule an export? No. Exports are produced on demand. The template slots are what make a recurring report a one-click job rather than an automated one.

Why is a column empty for most rows? Usually because the field only applies to some objects, and that is itself information. Traffic columns are empty where Zscaler reports no traffic in the window.

Flat or expanded for ZPA access policies? Flat for an inventory, one row per policy. Expanded when you need to analyse the conditions, one row per condition. Auditors generally want both.

Can I get the team’s comments into the sheet? Yes, with the collaboration columns, if Collaboration is enabled for the tenant.

The file is taking a long time. The export gathers data from the tenant before it writes anything. On large tenants that is the bulk of the wait, and the progress bar reflects real work.

Next steps

  1. Open the Exports menu and run the report closest to the question you get asked most
  2. Trim the columns to what the recipient actually needs, then reorder them
  3. Save it as a template so next month is one click
  4. Try matrix mode once on a multi-value field to see what it does to a pivot