Netskope Event Collector v2
This Integration is part of the Netskope Pack.#
Supported versions
Supported Cortex XSOAR versions: 6.8.0 and later.
This is the default integration for this content pack when configured by the Data Onboarder in Cortex XSIAM.
Configure NetskopeEventCollectorV2 in Cortex#
| Parameter | Description | Required |
|---|---|---|
| Server URL | True | |
| API token | True | |
| Trust any certificate (not secure) | False | |
| Use system proxy settings | False | |
| Max events per fetch | The maximum amount of events to retrieve per each event type. For more information about event types see the help section. | False |
Fetch Events Limitation#
The collector's capacity is at least 150,000 events per minute.
Commands#
You can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.
netskope-get-events#
Returns events extracted from SaaS traffic and or logs.
Base Command#
netskope-get-events
Input#
| Argument Name | Description | Required |
|---|---|---|
| limit | The maximum number of alerts to return (default: 10). | Optional |
| should_push_events | Set this argument to True in order to create events, otherwise the command will only display them. | Optional |
Context Output#
There is no context output for this command.
Command example#
!netskope-get-events limit=1
Context Example#
Human Readable Output#
Events List#
Id Timestamp Type Access Method App Traffic Type 23a372c433381a6a11798123 2022-07-17T23:48:52.000Z nspolicy API Connector Microsoft Office 365 Sharepoint Online CloudApp 9f806593aa4385e4fc14865c 2022-06-28T16:59:15.000Z nspolicy API Connector Microsoft Office 365 Sharepoint Online CloudApp efac69202c964c91fd59bcb9 2022-07-20T15:27:50.000Z admin_audit_logs e03cf756afc2a707666fcbc0 2022-07-13T19:54:57.000Z network Client [CS SEG's] PrivateApp