Netskope Event Collector
#
This Integration is part of the Netskope Pack.Supported versions
Supported Cortex XSOAR versions: 6.8.0 and later.
This is the default integration for this content pack when configured by the Data Onboarder in Cortex XSIAM.
#
Configure Netskope Event Collector in CortexParameter | Description | Required |
---|---|---|
Server URL | True | |
API token | True | |
Trust any certificate (not secure) | False | |
Use system proxy settings | False | |
Max events per fetch | The maximum amount of events to retrieve per each event type. For more information about event types see the help section. | False |
#
Fetch Events LimitationThe collector can handle 10K events per minute on average per each event type
#
CommandsYou can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.
#
netskope-get-eventsReturns events extracted from SaaS traffic and or logs.
#
Base Commandnetskope-get-events
#
InputArgument Name | Description | Required |
---|---|---|
limit | The maximum number of alerts to return (maximum value - 10000). | Optional |
should_push_events | Set this argument to True in order to create events, otherwise the command will only display them. | Optional |
#
Context OutputThere is no context output for this command.
#
Command example!netskope-get-events limit=1
#
Context Example#
Human Readable Output#
Events List:
Id Timestamp Type Access Method App Traffic Type 23a372c433381a6a11798123 2022-07-17T23:48:52.000Z nspolicy API Connector Microsoft Office 365 Sharepoint Online CloudApp 9f806593aa4385e4fc14865c 2022-06-28T16:59:15.000Z nspolicy API Connector Microsoft Office 365 Sharepoint Online CloudApp efac69202c964c91fd59bcb9 2022-07-20T15:27:50.000Z admin_audit_logs e03cf756afc2a707666fcbc0 2022-07-13T19:54:57.000Z network Client [CS SEG's] PrivateApp