Netskope Event Collector (Deprecated)
This Integration is part of the Netskope Pack.#
Deprecated
Use Netskope Event Collector v2 instead.
This is the default integration for this content pack when configured by the Data Onboarder in Cortex XSIAM.
Configure Netskope Event Collector in Cortex#
| Parameter | Description | Required |
|---|---|---|
| Server URL | True | |
| API token | True | |
| Trust any certificate (not secure) | False | |
| Use system proxy settings | False | |
| Max events per fetch | The maximum amount of events to retrieve per each event type. For more information about event types see the help section. | False |
Fetch Events Limitation#
The collector can handle up to 35K events per minute on average.
Commands#
You can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.
netskope-get-events#
Returns events extracted from SaaS traffic and or logs.
Base Command#
netskope-get-events
Input#
| Argument Name | Description | Required |
|---|---|---|
| limit | The maximum number of alerts to return (default: 10, maximum value - 10000). | Optional |
| should_push_events | Set this argument to True in order to create events, otherwise the command will only display them. | Optional |
Context Output#
There is no context output for this command.
Command example#
!netskope-get-events limit=1
Context Example#
Human Readable Output#
Events List#
Id Timestamp Type Access Method App Traffic Type 23a372c433381a6a11798123 2022-07-17T23:48:52.000Z nspolicy API Connector Microsoft Office 365 Sharepoint Online CloudApp 9f806593aa4385e4fc14865c 2022-06-28T16:59:15.000Z nspolicy API Connector Microsoft Office 365 Sharepoint Online CloudApp efac69202c964c91fd59bcb9 2022-07-20T15:27:50.000Z admin_audit_logs e03cf756afc2a707666fcbc0 2022-07-13T19:54:57.000Z network Client [CS SEG's] PrivateApp