Netskope Event Collector
This Integration is part of the Netskope Pack.#
Supported versions
Supported Cortex XSOAR versions: 6.8.0 and later.
This is the default integration for this content pack when configured by the Data Onboarder in Cortex XSIAM.
Configure Netskope Event Collector in Cortex#
| Parameter | Description | Required | 
|---|---|---|
| Server URL | True | |
| API token | True | |
| Trust any certificate (not secure) | False | |
| Use system proxy settings | False | |
| Max events per fetch | The maximum amount of events to retrieve per each event type. For more information about event types see the help section. | False | 
Fetch Events Limitation#
The collector can handle up to 35K events per minute on average.
Commands#
You can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.
netskope-get-events#
Returns events extracted from SaaS traffic and or logs.
Base Command#
netskope-get-events
Input#
| Argument Name | Description | Required | 
|---|---|---|
| limit | The maximum number of alerts to return (default: 10, maximum value - 10000). | Optional | 
| should_push_events | Set this argument to True in order to create events, otherwise the command will only display them. | Optional | 
Context Output#
There is no context output for this command.
Command example#
!netskope-get-events limit=1
Context Example#
Human Readable Output#
Events List#
Id Timestamp Type Access Method App Traffic Type 23a372c433381a6a11798123 2022-07-17T23:48:52.000Z nspolicy API Connector Microsoft Office 365 Sharepoint Online CloudApp 9f806593aa4385e4fc14865c 2022-06-28T16:59:15.000Z nspolicy API Connector Microsoft Office 365 Sharepoint Online CloudApp efac69202c964c91fd59bcb9 2022-07-20T15:27:50.000Z admin_audit_logs e03cf756afc2a707666fcbc0 2022-07-13T19:54:57.000Z network Client [CS SEG's] PrivateApp