Netskope Event Collector
#
This Integration is part of the Netskope Pack.Supported versions
Supported Cortex XSOAR versions: 6.8.0 and later.
This is the default integration for this content pack when configured by the Data Onboarder in Cortex XSIAM.
#
Configure Netskope Event Collector on Cortex XSIAMNavigate to Settings > Integrations > Servers & Services.
Search for Netskope Event Collector.
Click Add instance to create and configure a new integration instance.
Parameter Description Required Server URL True API token True Trust any certificate (not secure) False Use system proxy settings False Max events per fetch The maximum amount of events to retrieve per each event type. For more information about event types see the help section. False Click Test to validate the URLs, token, and connection.
#
Fetch Events LimitationThe collector can handle 10K events per minute on average per each event type
#
CommandsYou can execute these commands from the Cortex XSIAM CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.
#
netskope-get-eventsReturns events extracted from SaaS traffic and or logs.
#
Base Commandnetskope-get-events
#
InputArgument Name | Description | Required |
---|---|---|
limit | The maximum number of alerts to return (maximum value - 10000). | Optional |
should_push_events | Set this argument to True in order to create events, otherwise the command will only display them. | Optional |
#
Context OutputThere is no context output for this command.
#
Command example!netskope-get-events limit=1
#
Context Example#
Human Readable Output#
Events List:
Id Timestamp Type Access Method App Traffic Type 23a372c433381a6a11798123 2022-07-17T23:48:52.000Z nspolicy API Connector Microsoft Office 365 Sharepoint Online CloudApp 9f806593aa4385e4fc14865c 2022-06-28T16:59:15.000Z nspolicy API Connector Microsoft Office 365 Sharepoint Online CloudApp efac69202c964c91fd59bcb9 2022-07-20T15:27:50.000Z admin_audit_logs e03cf756afc2a707666fcbc0 2022-07-13T19:54:57.000Z network Client [CS SEG's] PrivateApp