Skip to main content

Lab 9 โ€“ SOC Triage with Workflow Automation

Lab 9โฑ 20 minโš— Enterprise Tenant ยท Read-Only๐Ÿ‘ค Priya
SOC Triage with Workflow Automation
As Priya, review pre-populated incidents in the Enterprise Tenant. Explore the incident queue, recorded evidence, notification history, and an existing workflow template. These are separate examples, not the events generated in your Module 2 Lab Tenant.
๐Ÿ”
Priya โ€” SOC Analyst (Tier 1)
Enterprise Tenant (Read-Only) โ€” Investigation Mode
You are Priya. The incidents are in the queue. Your job is to understand exactly what happened, build the full forensic picture, and determine the right response โ€” all without leaving the Zscaler console.

๐ŸŽฏTriage DLP incidents in Workflow Automation โ€” from queue navigation to incident drill-down to automated response templates.


Backgroundโ€‹

Return to the Enterprise Tenant using CloudShare โ†’ Credentials โ†’ SDC Credentials, as described in Lab 1. Keep the Experience Center Nav 1.0 interface for the navigation shown here.

As Priya, investigate a pre-populated inline DLP incident in Workflow Automation (WFA). Review its file metadata, policy, notifications, and state-change history to understand how incidents are handled.

Incident counts, dates, and available records may differ from the screenshots. If the example record is unavailable, select another Inline incident and review the same fields.


Task 1 โ€” Navigate to Workflow Automation and Open the Incidents Queueโ€‹

Workflow Automation is accessed from the main Zscaler console navigation bar. Follow the steps below to reach the Incidents list.

Stepsโ€‹

Step 1 โ€” Open Administration โ†’ Workflow Automation

From the top navigation bar, click Administration. In the drop-down, locate the Workflow Automation section on the far right and click it to switch context.

Navigate to Workflow Automation

Callout 1 โ€” Click Administration in the top nav. Callout 2 โ€” Select Workflow Automation from the sub-menu. Callout 3 โ€” Under Incident Management, click Incidents.


Step 2 โ€” Review the Incidents Landing Page

You are now on the Incidents list. It brings together incident records from the sources integrated with this tenant.

Incidents Landing Page

Observe the following on this page:

ElementWhat it shows
Date RangeIncidents from 2026-05-01 through today
All: 473Total incidents in the selected window
Open: 443Incidents not yet resolved
Unassigned: 468Incidents with no assigned analyst
Waiting Feedback: 30Incidents pending user justification
Escalated: 8Incidents flagged for senior review
Response Available: 17Incidents where an automated response is ready

The Priority and Severity quick filters at the top right let you surface Critical and High incidents instantly without opening the advanced filter panel.


Task 2 โ€” Filter by Source DLP Typeโ€‹

Use the Filters panel to isolate the available incident sources relevant to your investigation.

Stepsโ€‹

Step 1 โ€” Open the Filters Panel

Click the filter icon (funnel) at the top right of the Incidents toolbar.

Single Pane of Glass โ€“ Filter by Source DLP Type

Callout 1 โ€” Click the filter funnel icon. Callout 2 โ€” Select Source DLP Type from the filter category list. Callout 3 โ€” Check Endpoint and Inline under Include to see violations from those two channels side by side.

Available Source DLP Types:

  • Email โ€” incidents from ZIA Email DLP
  • Endpoint โ€” incidents from Zscaler Client Connector endpoint DLP agent
  • Inline โ€” incidents from ZIA inline proxy (web traffic)
  • SaaS Security โ€” incidents supplied by integrated SaaS data-protection sources

Task 3 โ€” Drill Into an Incident: Full Triage Walk-Throughโ€‹

Now open one of the inline incidents to see the complete forensic picture Zscaler captures.

Stepsโ€‹

Step 1 โ€” Open the Incident Details Page (Overview)

Click on Transaction ID 53-1282-7639608590483288010 โ€” the top-of-queue Critical incident โ€” to open its full detail view.

Incident Details โ€“ Overview

Read each section of the Overview panel:

FieldValue
Incident ID53-1282-7639608590483288010
System Creation DateMay 13, 2026 10:03:10 PM
Incident DateMay 13, 2026 10:03:08 PM
SeverityINFO
PriorityCRITICAL
ActionViolates Compliance Category
Source DLP TypeInline
Incident GroupsTEST, ayara-test, AA-Incident Group, Basic Inline DLP, BillTest
LabelsZI-2026-AMS:Hands-On Lab
IntegrationSDC Integration

Scroll to the Violation Details section:

FieldValue
Nameachan-sales@thezerotrustlab.com
Client IP54.255.194.66
DepartmentSales
StatusValidating with User

The example's Current State Details panel shows Validating with User. Review User Notifications and State Changes below to establish what actions were recorded; the status alone does not identify whether they were manual or automated.


Step 2 โ€” Review the Policy and Content Sections

Scroll down to the Policy and Content panels.

Incident Details โ€“ Policy & Content

Policy section:

FieldValue
RulesCC SSN HIPAA Block
Triggered EnginesExpand to see which classification engines fired

Content section:

FieldValue
File Nameattachment
File Typepost
File MD5b4bccb2a38701b3dbb6cb7111aed24a7
File Size1.32 KB
Document TypeNone

Application section:

FieldValue
URLdlptest.com/https-post/
Referrer URLdlptest.com/https-post/
NameDLP Testing Sites
CategoryCustom Capp
ProtocolHTTPS

The File MD5 hash is a pivotal forensic artefact. Priya can use this to verify whether the same file has appeared in multiple incidents, pivot into threat intelligence, or correlate with endpoint DLP logs.


Step 3 โ€” Review Violation Content, User Notifications, and State Changes

Scroll further down to the Violation Content, User Notifications, and State Changes sections.

Incident Details โ€“ Trigger Data & State Changes

Violation Content:

  • Generate Presigned Link โ€” produces a time-limited URL to retrieve the actual violating file content (subject to tenant permissions).
  • View Trigger Data โ€” shows the raw data that fired the DLP engine, including matched content snippets and engine confidence scores.

User Notifications table:

UserRoleChannelStatusAttemptsNotified
achan-sales@thezerotrustlab.comOriginating UserEmailNot Responded1May 13, 2026 10:30:01 PM

State Changes audit trail (most recent first):

StateDateChanged ByComment
Presigned UrlMay 13 11:13 PM1242058-adminGenerated Presigned Url
Add LabelsMay 13 10:53 PMjiqbal-adminAdded label: ZI-2026-AMS:Hands-On Lab
Note to the UserMay 13 10:30 PMca-0019-adminPlease justify uploading this document for testing purpose of HandsOnLab.
Notify UserMay 13 10:30 PMca-0019-adminNotified achan-sales over Email
Change StatusMay 13 10:30 PMca-0019-adminChanged status: New to Validating with User
NewMay 13 10:03 PMSystemIncident Created

Use State Changes to review the recorded actions, timestamps, actors, and comments. The example attributes notification and status changes to an administrator; identifying a specific automated workflow would require additional evidence.


Task 4 โ€” Explore Available Actionsโ€‹

Return to the top of the Incident Details page and open Actions. Review the available options without executing them; this exercise explores existing records in the read-only Enterprise Tenant.

Incident Actions Drop-Down

ActionDescription
Assign DLP AdminRoute incident to a named DLP administrator
Assign PriorityManually override the system-calculated priority
Assign to MeClaim the incident for personal investigation
Close IncidentMark the incident as resolved and close it
Create Policy ExceptionAllow the triggering pattern for this user or content type going forward
DeleteRemove the incident record (audited)
EscalateBump to senior analyst or management queue
LabelTag the incident for reporting or grouping
Notify UserSend a manual notification/survey to the originating user
InvestigatingSet status to indicate active analyst review
TicketCreate a linked ticket in an integrated ITSM (e.g., ServiceNow)
Update Incident GroupMove incident to a different incident group

Task 5 โ€” Explore Workflow Templatesโ€‹

Priya has reviewed an incident and its recorded history. Next, preview an existing workflow template to understand how notification and escalation can be automated; no workflow configuration is required in this lab.

Stepsโ€‹

Step 1 โ€” Navigate to Workflow Templates

In the left rail of Workflow Automation, expand Workflows and click Workflow Templates.

Workflow Templates List

Review the available templates. Examples shown include:

Template NameDescription
Auto Close Data Loss Protection Incident With Resolution La...Automatically resolves the incident and adds a resolution label
Auto Close Data Protection IncidentAutomatically sets status to Resolved
Auto Create TicketsAutomatically creates a ticket in ServiceNow or Jira
Auto EscalateAutomatically escalates to the user's supervisor or approver
Auto NotifyAutomatically notifies the originating user via the configured channel
Auto Notify User and Close IncidentNotifies user then closes the incident in one step
Auto Notify User and Concurrently EscalateNotifies user and escalates simultaneously
Auto Notify User and EscalateNotifies user first, then escalates

Review the Counts column and available mapping details. A count alone does not establish that a workflow ran for the incident you inspected; check its mapping criteria and execution evidence.


Step 2 โ€” Preview the Auto Notify User and Concurrently Escalate Template

Click the eye icon next to Auto Notify User and Concurrently Escalate to open the workflow preview.

Workflow Template โ€“ Auto Notify and Concurrently Escalate

Read the visual workflow diagram:

NodeDescription
StartTriggered when a matching incident is created
Notify UserSends notification to the originating user
Get User ManagerLooks up the user's manager in the directory
Check Manager ExistDecision node โ€” does this user have a manager configured?
Escalate to ManagerIf manager found โ€” escalates to the user's direct manager
Escalate to ApproverIf no manager โ€” escalates to a pre-configured approver
EndWorkflow completes

The right panel shows the configurable settings:

  • Escalate to Manager โ€” Notification Channel + Language
  • Escalate to Approver โ€” Approver Name + Notification Channel + Language

This single template replaces what would otherwise be a multi-step manual process: notify, look up manager, escalate, confirm. It executes in seconds, automatically, for every incident that matches the workflow mapping criteria.


Lab Summaryโ€‹

In this lab, Priya explored a pre-populated incident and response workflow:

  1. Navigated to the Incidents queue via Administration โ†’ Workflow Automation
  2. Reviewed queue counts and statuses for the selected reporting window
  3. Filtered by Source DLP Type to compare Inline and Endpoint records
  4. Inspected an incident's user, file metadata, application, and policy details
  5. Reviewed recorded User Notifications and State Changes
  6. Explored available response actions without executing them
  7. Previewed an existing notification-and-escalation workflow template

Key Takeaway: Workflow Automation is not a passive log viewer. It is an active SOC workspace where detection, investigation, user notification, and automated response all converge โ€” replacing the multi-tool, multi-console workflow most security teams operate today. The State Changes audit trail and Workflow Templates together deliver both compliance evidence and operational efficiency.


๐ŸŽ“
Lab Assistant
Zenith Live 2026 ยท Dataparity
Lab 9 โ€” Investigation
Browse all topics