Zscaler ZIA Admin Audit - High-Risk Policy Change
This rule monitors for high-risk modifications to Zscaler security policies such as disabling SSL inspection or DLP engines, or deleting/modifying firewall and URL filtering rules. It also flags administrative logins from locations previously unseen for that user, which may indicate account compromise or unauthorized access.
Splunk (SPL)

