---
title: 🔧 How to Troubleshoot Zscaler Client Connector (ZCC) Logs
description: "Audience: IT support staff and engineers\nPurpose: Help you quickly locate and resolve application or connectivity issues using ZCC logs and basic diagnostic tools."
---

[Skip to content](https://securedynamics.net/kb/how-to-troubleshoot-zscaler-client-connector-zcc-logs#main-content)

English

Show submenu for translations

![SecureDynamics Zscaler Logo](https://securedynamics.net/hs-fs/hubfs/SecureDynamics%20Logo%20Dark-1.png?width=1250&height=296&name=SecureDynamics%20Logo%20Dark-1.png)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- Go to securedynamics.net

 Go to securedynamics.net

 Hello. How can we help you?

- There are no suggestions because the search field is empty.

1. [SecureDynamics Knowledge Base](https://securedynamics.net/kb?hsLang=en)
2. [Support](https://securedynamics.net/kb/support?hsLang=en)

# 🔧 How to Troubleshoot Zscaler Client Connector (ZCC) Logs

## Audience: IT support staff and engineers Purpose: Help you quickly locate and resolve application or connectivity issues using ZCC logs and basic diagnostic tools.

#### 🧰 Step 1: Orientation Before You Dive In

Before jumping into logs:

- Make sure support staff understands **PAC files** (used for web traffic routing) and how they work with ZCC.
- Know the basics of **Z-Tunnel 1.0 vs 2.0**, even if you don’t manage tunnels directly.
- Understand that **PCAPs (packet captures)** can be aligned with ZCC logs by timestamp — even without deep packet inspection skills.

---

#### 📂 Step 2: Open and Search ZCC Logs Like a Pro

Unzip the logs and open the most recent **ZSATunnel.log** file.

Use a good text reader — **Notepad++** is great, but for even easier navigation, try **cmtrace.exe** (from Microsoft Endpoint Configuration Manager). It’s a lightweight, high-speed log viewer that highlights errors automatically.

🔍 Search for keywords:

- `Exception`
- `Fail`
- `Error`
- `Down`
- `Crashed`
- `Invalid`
- `Compromised`
- `Detected`

➡️ **Pro Tip:** Look 5–10 lines above and below any match — the cause often sits nearby.

---

#### 🌐 ZIA-Specific Log Checks

When troubleshooting **Zscaler Internet Access (ZIA)**:

- Search for `FindProxyForURL` to see how URLs are routed.
- Check `PAC Parse Host` and `PAC Parse Action` for logic issues in the PAC file.

---

#### 🔒 ZPA-Specific Log Checks

When working with **Zscaler Private Access (ZPA)** logs, these terms are gold:

| Keyword | Why it Matters |
| --- | --- |
| `QRY=SRV(33)` | DNS lookups for Active Directory — check against PCAP for match |
| `mtunnel` | Core ZPA tunnel status |
| `NXDOMAIN` | DNS failure (non-existent domain) |
| `ERR Connection to ZPN` | Tunnel routing failure |
| `100.64.0.6` | Sign of firewall or AV interference with SYN packets |
| `Connection Reset by Peer` | Session closed by remote system |
| ZPA Session Status Codes | Always worth reviewing for policy or network mismatches |

🖥️ Ronnie Meekers, a longtime Zscaler partner, recommends:

> Run `netstat -an 1 | find /I "SYN"` on Windows or similar commands on macOS to find apps using hardcoded IPs. These often bypass ZPA, especially in legacy VPN environments.

---

#### 🧠 Helpful Community Tips

- Use the **search tool on community.zscaler.com** to access both new and archived troubleshooting guides. Many topics from the legacy community still apply today.
- Here's one worth bookmarking:  
  [Zscaler Troubleshooting Tools for Connectivity and Slowness](https://community.zscaler.com/s/question/0D54u00009evmmOCAQ/zscaler-troubleshooting-tools-for-connectivity-and-performanceslowness-issues)

📚 Original Article: [Learning How to Troubleshoot ZCC – Zscaler Community](https://community.zscaler.com/s/question/0D54u0000AeX46cCQC/learning-how-to-troubleshoot-zcc)

---

#### 📤 Sharing Logs with Support

1. Open ZCC \> click the **gear icon**.
2. Select **“About” \> “Collect Logs.”**
3. Save the ZIP file and email it to your SecureDynamics engineer or support contact.

---

We are Zscaler Delivery Services Authorized, providing the best deployment experience possible.  
Thanks for choosing SecureDynamics, Zscaler's most trusted and comprehensive partner.

- [FAQs](https://securedynamics.net/kb/faqs?hsLang=en)
- [Troubleshooting](https://securedynamics.net/kb/troubleshooting?hsLang=en#main-content)

    - [Client Connector Portal](https://securedynamics.net/kb/troubleshooting?hsLang=en#client-connector-portal)
    - [Zscaler Client Connector](https://securedynamics.net/kb/troubleshooting?hsLang=en#zscaler-client-connector)
- [Support](https://securedynamics.net/kb/support?hsLang=en)
- [SecureDynamics Internal](https://securedynamics.net/kb/securedynamics-internal?hsLang=en)
- [Licensing](https://securedynamics.net/kb/licensing?hsLang=en#main-content)

    - [ZIA Upgrades](https://securedynamics.net/kb/licensing?hsLang=en#zia-upgrades)
- [Education & Training](https://securedynamics.net/kb/education-training?hsLang=en)
- [Delivery Services](https://securedynamics.net/kb/delivery-services?hsLang=en)
- [Partner Help](https://securedynamics.net/kb/partner-help?hsLang=en)

[![SecureDynamics Zscaler Logo](https://securedynamics.net/hs-fs/hubfs/SecureDynamics%20Logo%20Dark-1.png?width=1250&height=296&name=SecureDynamics%20Logo%20Dark-1.png "SecureDynamics Zscaler Logo")](https://cm360.securedynamics.net?hsLang=en)

securedynamics.net Help Center

Copyright © 2026, SecureDynamics

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://securedynamics.net/#organization",
  "@type" : "Organization",
  "address" : {
    "@type" : "PostalAddress",
    "addressCountry" : "US",
    "addressLocality" : "Santa Clara",
    "addressRegion" : "CA",
    "postalCode" : "95054",
    "streetAddress" : "5201 Great America Pkwy, Suite 320"
  },
  "logo" : {
    "@type" : "ImageObject",
    "url" : "https://securedynamics.net/hubfs/SecureDynamics%20Zscaler%20Logo-1.webp"
  },
  "name" : "SecureDynamics",
  "sameAs" : [ "https://www.linkedin.com/company/3626024/" ],
  "url" : "https://securedynamics.net/"
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://securedynamics.net/#website",
  "@type" : "WebSite",
  "inLanguage" : "en-US",
  "name" : "SecureDynamics",
  "potentialAction" : {
    "@type" : "SearchAction",
    "query-input" : "required name=search_term_string",
    "target" : {
      "@type" : "EntryPoint",
      "urlTemplate" : "https://securedynamics.net/hs-search-results?q={search_term_string}"
    }
  },
  "publisher" : {
    "@id" : "https://securedynamics.net/#organization"
  },
  "url" : "https://securedynamics.net/"
}
```