logo

NJP

Amplify ServiceNow's Capabilities with Zscaler's Digital Experience (ZDX)

Import · Jun 21, 2023 · video

uh hello everyone and welcome to the webinar all right so uh today we are going to mainly focus on uh rescalers partnership with servicenow and uh one of the key one of the things that the internet now that we have realized is that the internet is now the new corporate network uh and it operations teams can now observe all your networks rely on them improve productivity Etc and what comes with that is we are looking at uh accelerating our mptr through precise uh issue detection root cause analysis Etc and then expand and expand uh and support the digital Workforce quickly and confidently that's the main theme that we are focusing on with our partnership with servicenow as mainly for integrated and comprehensive Solutions so the first one we all know it as the scalar internet access this is one of our first products the most widely uh spread product uh this mainly focuses uh on Cyber protection data protection basically making your internet access secure for your sat application we also have a cscaler private access which is uh which allows you to remotely access your private applications data centers without the need of a VPN and it uses our zero trust exchange as well uh and then last but not least we also have a detailer for workload so all your workloads communication across your hybrid clouds identity page workload segmentation everything is taken care by easy slip or workload application so now one of the new breeds of products that we have uh released in the last couple of years is the Z scalar digital experience product now what this does is we are in the business of securing your access to the internet however with ZDX we are able to provide you uh performance and availability experience across your users applications different locations and then allow you to identify and resolve devices and network issues and we will see this as we move forward in the presentation now the V scalar zero trust exchange is a cloud native uh platform and that acts like a kind of a switchboard so it verifies your identity uh and the context it applies the controls to ensure that you're not getting any threats or leaking any sensitive data and then enforces policies to determine whether to connect you to the destination resource or not and as part of this zero trust exchange vdx is the only solution that provides a unified way of performance from the device through the network up to the application and uh and up to your like if it is a private application then we also go look into your data center-based applications as well and with that we also uh focus on providing you with root cause analysis that exposes any offenders impacting your uh user experience now uh as we know today and what we have seen in the past couple of years a majority of our organizations have adopted a digital first business strategy and to support this transformation cios have welcome uh Cloud applications and SAS applications incidentally your organization which are almost more uh any organization with more than 250 users uh use more than 100 SAS application and that that was just staggering for me uh and this workloads migration to the cloud uh from what we have seen by 2024 we see that the Enterprise will probably be spending eight out of the ten dollars uh for it hosting going towards the cloud so as apps and data disperse to the cloud teams have been uh have added additional performance monitoring Telemetry to their Arsenal so they get visibility across all their assets and on also the application that sit in the cloud and in the meantime uh the workplace as we know has also changed with hybrid workplace gaining broad acceptance employee rely on their home Wi-Fi networks uh their local isps and uh this is basically two access application directly and of course a cloud and private applications as well that you are hosting and with that in place they are bypassing all of the security controls that you may have put in painstakingly in that one physical location over the years that just changed uh instantly overnight now this new workplace Dynamic is here to stay it is putting a lot of pressure on your network operations team your service test team and of course your secure teams as well it's just a headache for now for them all three of these players today now they see greater than 35 increase in their support ticket volumes and and a rise of more than about almost 30 percent in service cost per ticket it's because the information that they are looking for is simple not available to them at any given point in time so making matters words uh your network operations and service desk teams today have Point solutions that leave them unprepared so they may have Solutions in place for monitoring your devices your network your application but they're all disparate right and that leaves blind spots caused by the users uh devices or the network or the application uh even if they have been able to monitor all of these things what happens today is whenever an issue occurs they have to manually correlate data across all these different applications now yes you can automate this by using apis integrated in a third-party application but still you are looking at information from different solutions the triaging looking at that uh solution and then making a decision as to where the problem is now this lack of end-to-end visibility in your digital experience forces your teams into uh firefighting problems after they have been reported so nobody is monitoring anything proactively right when something happens is when we all basically come and react towards that particular situation now the other thing is you may have solutions that are monitoring your devices Network and applications right and all of these is possible by something that you install or an agent that is sitting over there that is constantly keeping an eye on all these things with that comes a tedious maintenance jobs to update these agents making sure that they are all on the latest version they are all compatible with your network or devices Etc and that's just one more hassle for your it team to manage and last but not least every single application including ours we do have an alerting capability and what we have seen in the past is a we are not either very good at setting up alerts or we want to make sure that we have visibility into everything and we create multiple alerts what that causes is an alert fatigue because now you're getting alerts from Fields different kinds of applications all at once and you have no idea which one to focus on because you do not have the ability to correlate these two alerts to see if they are the same or they are two different things now z-scaler gives you a visibility to need to ensure your digital experience for all your users within the office homes and also those people who are on the move right so by securely monitoring your business's SAS applications your private applications your data centers Etc right from within your end users devices gives you the complete visibility as to how a user experiences uh connectivity to these applications now ZDX is able to present a user experience inside across your organization you can even check an individual user as to how they are experiencing performance to any of these applications and along with that we provide you an end-to-end view of the performance availability across your entire application delivery chain now also with regards to uh working from home and the hybrid nature of things we today rely on different applications like either Microsoft teams Zoom or even WebEx and we have partnered with all three of these vendors to bring to user apis to bring in Telemetry data into ZDX and what we do is uh using the machine learning uh capability that we have built from the ground up uh we are able to accurately expose root cause by looking at the information from past experiences ensuring that IIT addresses the core issues causing for experience and not just a symptom so we are able to Bubble Up things to the user in real almost real near real time to say where they are having a problem and what kind of problems they are having so uh when you have CDX uh every every portal does have the ability to run these machine learning uh capabilities from the portal itself so we use machine learning to accurately expose the root cause by looking at information for a given user uh what kind of context the user has so uh what kind of an ISP provider they are using what kind of application they are using uh are there other users in the same uh area or a geo geography are they using similar ISP providers or the same ISP provider and of course application based on all this information that we get we are able to identify with almost 99.5 accuracy as to what is the problem that the user is facing and this is really really helpful to our service desk personas because now instead of going through all the data that you have collected to identify where the problem lies you can simply click a button to get this particular uh root cause instantly in within seconds to tell the user I know what the problem is and this is how you can resolve it or escalate it to the level two uh support with the relevant information that they will require to resolve that particular problem now uh one of the use cases that we talk about so when you get ZDX in uh when you have ZDX portal uh let's consider a scenario where your network operations teams is monitoring all your SAS applications your private applications uh which are basically critical for your office environments now here right on the dashboard you will basically see a global view of how your apps are performing across all your users now here you can see uh that while workday and box are performing well looks like I have a green bar for both of these applications my score is also very good 97 out of 100 those looks good but when you look at OneDrive I'm noticing that there's some areas of concern for me over here now looking at the map I can clearly see that in India there are a couple of locations over here that are having a very high uh problem over here where the users are experiencing major problems you can drill down on to that particular location identify the users who are impacted by this particular outage and then basically go look at it and see where the problem lies so in this case over here I was able to see that there is uh I was able to narrow it down uh to a network very high Network latency between an ISP provider called psnl and the Washington Redmond Washington servers for Microsoft Office so that's where I have very high latency over here so uh the network team was able to look at this and this is actually an actual example they were able to look at this information raise a ticket with Microsoft in order to solve this problem for them at therein now here is another example this one was basically a zoom outage that we detected in September 2022 now we at vdx at vscaler also use CDX so we believe in drinking our own champagne and we do monitor some of the business critical apps that we have in uh we have in place uh in our organization so while we were looking at our dashboard we noticed that Zoom was having a significant problem and it just showed up red for every single uh geography that we had now I looked at all the other application they all seem to be fine SharePoint was doing great so it's now us doing great and then I was able to drill down into zoom and see that while Zoom was doing well until a certain time it suddenly dropped and to almost a zero score which basically triggered me to see that something is upgrade soon I was able to further drill down or look or zoom into it and see that the zoom out it started at around 7 55 am there was a significant drop on everything it probably lasted about 20 minutes while the services were able to recover by about 8 25 so about 30 minutes of downtime is what everybody experienced uh I was able to go pick a few users who were online at that time and see that on the page uh uh on the web ropes we were able to see a 502 response that we were getting from uh Zoom so basically there was just literally no activity our sir our server response time also was not available [Music] it ran the machine learning capability in the background and once the results came back we were able to see that it looks like there was a bad performance across Zoom globally and not just it was impacting us uh later on we also looked at our network path and it looks like the network path was was showing the end user that they were able to reach the destination it was something up with their web performance itself and uh after a while when Zoom was able to uh resolve that particular issue they updated this uh on their uh status page so they basically reported at 8 17 whereas we were able to detect the outage right at 7 55 am when it started uh so that was basically the power of CDX having installed in within our uh within your organization now to make things more proactive yes our platform also provides the ability to uh send out alerts and notifications now when it comes to metrics we allow you to set up alerts uh at almost a very granular level so you can look at response times or server response time DNS uh if your availability is available uh is good or not uh when it comes to network you can look for packet loss latency and hop count and of course we also monitor the health of your devices so you can set up alerts to identify if there are people or a group of people who are having high CPU or memory consumption and things like that uh one of the main aspects of our alerting is the ability to throttle these alerts so you can throttle the alerts in the sense that you don't want to receive an alert when one user is having a problem or there's one impacted device in the entire geography you can throttle these alerts by saying that at least a minimum of 10 users are impacted uh in a given geography so that way you are reacting to something that is impacting a lot of users instead of that one single user and of course we can send out notifications by email or webhooks and webworks is what we use to integrate with service now today uh we also have a brand new kind of alert that we released uh very recently called Dynamic alerts and what this does is uh it basically monitors a specific metric now uh we know that people are working from different locations their latencies to a particular server is not going to be the same as everybody else things change the depending on the proximity to the uh the server that you're connecting to you may have a better or inverse CDX score so what we have done now is instead of giving hardcore thresholds you can set up a alert based on the sensitivity of the drop of cctx alert so this way you don't have to worry about setting up thresholds or setting up multiple alerts for different geographies you can simply say that if my score deviates low medium or high sensitivity to the current Baseline only then send me an alert so this illuminates a lot of other issues that you may have by getting false positive alerts on your platform now uh for RZ scalar digital experience and servicenow use cases uh we do have the ability to send out web hooks to servicenow today into your itsm as an incident or your item uh as an event this we do have the vdx application available in the servicenow marketplace and once you install it you will be able to set up web hooks that send out events or incidents uh immediately to servicenow itself and to show that capability I will pass on to William who can go through a short demo William sure so let me share my screen here in a second and if you're hope everybody can see my screen there so yeah so I'll go very briefly here on what we currently have integration wise with the services now when it comes to uh dedicated applications so just to get started here at the the very the very first thing if you go into the service noise store you're in the search for a z-scaler you're going to find two different applications that we we currently provide one is the event management event and just mentioned a few seconds ago that basically sends the actual events from ZDX into the item solution okay so there are more details into the within the the actual application here the one that we I'll be focusing today on this demo is the uh the scalar digital experience which is the elsewhere webhook API integration but this is the itsm based uh only integration so um right here uh as you can see a very traditional summary uh with what the application does and some screenshots so if you're free to visit and take a look at it and send us any questions regarding that so from a ztx perspective right so if we search it here into amend my service no instance and if I search for z-scaler uh we once I installed the app I now have the zscaler digital experience application right here so there are several things here we provided a guided setup as well where you can basically configure the application the integration itself configure API Keys usernames required and things like that right so it's very interactive that way um and that was a way to actually contact our support team is a very traditional guided setup and help help Porto uh design as well that we provided here but for this demo what I will focus on here is on the services now incident so it's a table we create where we accumulate all the incidents or aggregate all the incidents that are being uh created by the ZDX platform itself so based on the API uh webhook calls that are sent to service now with the Json payloads those are sent here and automatically parsed by the the scale of digital experience application and the incidents are automatically created so if I filter by one of the incidents here to share details of how those incidents look like so filtering by one of these incidents I can go in here and then very traditional way of actually looking at the incidents so look from the from the over my tier one help desk analysts perspective most of most of the the time uh organizations uh that work with this Scala they don't want to tier one and help desk analyst to login into the ZDX Porto itself they want them to keep on using service now as the single pane of glass to analyze and investigate or do that initial investigation of incidents affecting the end users experience so any alerts generated by ZDX are basically uh assigned and obviously an alert ID and uh there are inside the description field we actually provide a variety of different types of information such as which locations departments the number of operating systems or devices that haven't been affected by that particular alert so as Venda mentioned a specific alert a specific event that happened at Zoom uh that would automatically create a trigger an alert incident in the scaler and uh and ZDX will trigger uh basically an incident inside service in our uh that would allow the help desk analyst restart an investigation or at least an escalation as an escalation point but as you can see we can look here that the root name that was created on the Z scalar side is basically called of senior uh often pronouncing this right but and basically it reaches the certain threshold that essentially trigger this alert so at the very bottom here um obviously this other fields I'll always skip those because those are very traditional for service in all applications itself in terms of the notes and the related records and things like that but the most interesting part on this screen here uh is the Deep tracing deep tracing is a native capability inside the ZDX itself so think historically how we use it to perform turbo shoot in troubleshoot with the user uh when the user contacted us saying that the internet was low or they couldn't access a specific application we typically would be on the phone uh with the user asking them to run commands such as Trace Tracer or Trace router ping and most users the first question would be what is that because they barely could even type the comment themselves but at the at a nutshell here what deep tracing does is to perform to allow the uh tier one analyst or any analyst for that matter to performed more of a remote troubleshooting slash diagnostic of the end user's endpoint itself so let's assume that this particular user have is experiencing uh performance issues with their desktop or or to act as a specific application so the first thing that will an analyst can do is to basically click here in deep tracing and obviously there is an instance that name here and I can actually uh choose how long do I want that deep tracing to run so what deep tracing will just prefer additional context here what that will do is to run specific probes on the endpoint or on the from the end point to the actual application itself so it's gonna call I'm going to collect metrics such as if you memory Wi-Fi signal or internet performance the information things along those lines so it's going to collect up a right of the different types of information but without you having to actually log into the end user's endpoint itself so I can choose it here how long I want to run this this deep tracing four so if I choose here five minutes I can then choose which user do I want to actually run this uh uh this deep tracing for right so I think of the name here isn't correct so I'm basically filtering here by this particular user in this case and uh automatically hear what's going to happen is that uh zdi the the service in the service Now application actually is performing API calls back into ZDX to basically map which endpoints are associated with these this particular user here in this situation I can now choose like what type of probe or or tracing do I want to run do I want to run a local Probe on the endpoint where I can collect device metrics or do I want to actually run an application a specific to certain applications so let's assume here that this user is having problems with Salesforce so ZDX has several uh different applications that it currently support uh so I'm not going to run this one here but I just wanted to wanted to see here that the application typically will be listed here in this case so it takes a little bit of time to come up but at the next show it would show here hey uh run a dick tracing for uh including uh Salesforce and I can basically say what type of probe do I want to run is it a web probe only where I'm going to basically be fetching the pages itself uh and and calculating how long is it taking for that page to be fetched or do I want to also run uh we can pick here and basically say you can see here this is just basically how long is it taking for for me to fetch the page itself and uh and how long is it taking to respond back but I can also actually collect the metrics that say give me all the metrics uh from the endpoint itself all the way to the actual application so in this case here it's gonna give me everything uh related to the application and then point overall at a at the very last year what you can optionally do is to establish okay I just want to actually grab information if uh the packet loss is supersedes a specific percentage or the latency is higher than or or lower than right so again this is an optional field so most of the time uh what the analysis will do they want to everything they don't want to only specific uh packet loss percentage because they sometimes just don't know what that actually entails for the most part but once I actually do this I can click and save that will save my my uh my uh deep tracing here it takes a few seconds to pop up here that it's saving and then it's gonna trigger an API called choose edx just say hey proceed with the probe it's with the probe right so that's safe to know and then on my list of deep tracing here and that's actually uh lists the a history of all the potential deep traces ran in this particular incident right here so by that second here it's gonna load and here I go it was so there's a probe created right here and if I go now uh I have two choices if I have access to the actual ZDX uh portal as administrator uh or read-only administrator access I can either click here on the Deep link and that if it wants the deputy Trace is actually done it's gonna show all the data in here though what is collected there's nothing right now because it didn't finish running yet but just for sake of this damage we expedite thanks uh if I go back into the ZDX administrator portal and this is basically all the maps uh that uh Venom showed earlier and those are all the applications that are currently being monitored up to here I can actually go under Administration and deep tracing and you can see that that deep tracing that I triggered with this incident name is actually now here so and you can see that it's actually monitoring for a particular application obviously five minutes is not enough most in some depending on the situation unless it's a very active incident that is going on so we may end up not having anything at the end of this five minutes and obviously I'm not gonna make you guys wait five minutes to have the result here but let's pick an instant here where the dick tracing was concluded to see what actually it would show you uh at the end of the the the end of the probe so I'll pick any incident here I just want to show you guys the end result of how the the actual deep tracing would look like so if I go in here for example uh and pick like device and application so those are two different two probes as I showed you earlier and if I click on the little uh I icon right here it's actually gonna give me uh some context for example here it's not showing a lot if you're going to pick another one uh one of us to have a here we go so it's a this is a different user but it's about and it's a box application but uh and the result would be similar in terms of what the visibility is giving you but it's showing you here how long it's taking for the page to be fetched and uh the how long is it taking for the server to respond uh how long is it taking for a DNS resolution to come back right so availability there's a lot of information as you can see here so again these are things that the vendor showed you showed earlier on the slides but the basically the cloud path from the end point all the way to the application uh where there are potential latency uh latency issues for example across the internet path but it also shows you hear like the actual end to end that from there who end point it doesn't matter where the user is it can be at home he can be uh on the road at an airport as long as they are connected to the scalar which is a scalar client connector agent and uh sending traffic through the scalar we will be monitoring that user so but as you can see here in very in a lot of details from this from this user as endpoint to the Wi-Fi uh hotspot where they are connected there's 173 milliseconds of time response time and you can expand the business hop to hop uh path of how actually this uh this user may be experiencing any issues here right all the way to the end passing through this scalar data centers and then you can expand even further and see all the way to the end where the actual application is hosted so for those that are more common line junkies like me so you can actually see those but like the traditional Trace routes and uh and additional information IP address related and hop Direction and and a lot of information a more common line view time and uh finally here at the bottom you would be able to see device events itself so if there is a device event related to the z-scaler client connector event or network related event or software-based events as well so there's a lot of information and visibility which will give you indication of where the potential root cause of the problem is and what measures potentially you can take given depending on your playbook uh that can measures you can take to actually solve the problem or potentially escalate to the responsible teams as well so obviously the question that always comes up is like okay this is these are some very cool dashboards and things like that but why in the world you're not putting all this in here and that's where I pass the button back to London I will give you guys some uh some uh some insight on where we're heading with this integration all right thank you thank you so much William I will re-share my screen and I hope I share the right screen this time you're good right all right all right so uh what William showed was the existing integration that we have today and we are not stopping that we are doing more Integrations or enhancements to what we have built so far so one of the first things that you will start seeing in the upcoming months is a deeper integration using our API so our web hooks are uh are kept lightweight for a purpose so that we don't send you way too much information and slow things down we want to keep it as simple as possible but the important information is always available in the webhook now with the with the apis uh available now uh one of the things that we are doing is the any metadata information that is available in the webbook we will use that to pull in the relevant information to bring it into servicenow itself so here you can see the alert web hook that was being sent to you is now now enhanced to basically include much more descriptive data in the sense you can see what departments have been impacted what are the major geolocations that were impacted by this and also if you have uh z-scaler local location setup you'll be able to see that as well and last but not least you will also see another tab called impacted users where you can go in and see the list of all users who were impacted by this particular alert that you had set up now the other thing that we are doing is there is always users who will create a ticket remember the use case scenario where you want to monitor for groups of people impacted but there's what happens when an individual user is being impacted now if they are creating a ticket in service now in this example I have Curtis uh Chris Curtis uh saying that hey he's having some problem with OneDrive uh we will be able to identify that the user in square skirt is and again by using apis we are able to pull in the information for Chris Curtis's uh devices so here in this case I can see if the user has two devices uh all the applications that are being monitored from his device and the relevant score for each device and I can see that OneDrive is having a problem now with this we are also going to introduce a new kind of uh action that you can take in service now is to basically click on the analyze code that will run the machine learning algorithm in the background get either relevant information that you need as you saw in the previous play uh example and provide that information right here within servicenow so your support staff will have enough information to play with to ensure what the issue is they're communicating well with the customer and these are happening within seconds and of course if they can't resolve something they can always escalate it to the next level now last but not least there is always a scenario where you may want to get more information now one of the latest features that we have rolled out recently is we are calling it snapshots but what that does is it provides you the ability to build a URL that you can share with colleagues or even outside your organization and with that what will happen is you can create uh links to provide contextual information you can offer State private data if you want to so in case you're sharing it outside your organization or you don't want the level one support to know uh more details about or the more private details about the user you can choose to do that as well and of course you can set an expiry date for these links so after two days or three days or 30 days these links will expire so uh and one of the most important aspects of these snapshots is that when you click on these uh if you do not have access to CDX portal you will still be able to see the information it'll bypass the login but the information is going to be a read-only information so you can go through all the metrics that we have captured see where the problem is and then communicate with the user uh so if you want to learn more about our research integration stay tuned on the ZDX Market the app is constantly being updated as we do a lot of new features there is also a video available on the z-scaler resources page and you can also of course sign up for a demo on freescaler.com and out using this particular link uh with that I uh turn it on towards you if you have any questions I'll be more than happy to answer them and uh let me know your feedback real quick London I'm going to launch our poll to see if we have any anyone who'd like to get a follow-up uh folks are still on the call please uh indicate if you'd like to get a personal um you know message from z-scaler after this webinar and um so you get a personalized demo or some help with the uh with the integration um we did have one question coming in the chat from mukul do these incident related lists specific to this integration of any role based visibility or are they open to anyone with access to the incident so at the moment uh the incidents are directly basically sent from the web hook so uh once the Web book is created uh it just flows into service now now uh we don't control any kind of rpac on servicenow site and William you can correct me if I'm wrong over here no I'm not sure I understood fully the question there yeah I think what they are looking for is uh a related list the incident list specific to this integration have role-based visibility or open to any one access to the incident so whoever has access to the services instance right uh unless you're doing like Access Control inside service now itself uh they will potentially have access to the actual incident itself now the Deep link I showed earlier that will depend if the person clicking on the Deep link has access to the ZDX instance site right so uh on our side we have a lot of Access Control uh uh row based access controls where you can give only uh read-only access only to analysts for example if you want so they can't perform any configurations in ZDX but okay they can still visualize reports and the metrics and things like that so to it to your question the the it will depend on if you're controlling access or visibility access inside service in our itself but uh from our standpoint on the application natively there's no no way to control that you William all right any other questions from the uh um webinar attendees all right well um thank you so much for the the detailed deep dive um we really appreciate the z-scaler team coming on and sharing this with us today uh the integration is um obviously still evolving and getting even better so we hope that you um follow up on this content go to the servicenow store.servicenow.com type in zscaler and you will see all the offerings at um Divya bonded and their teams and their teams have worked on over time and with that

View original source

https://www.youtube.com/watch?v=DY34CFBNkDU