Netskope

Collect security events from your Netskope platform including application usage, network traffic, alerts, DLP incidents, and user activity.

Ingest Methods

RunReveal offers the following ways to ingest Netskope logs:

API Polling

Netskope supports API polling to collect audit logs from your Netskope account.

For detailed setup instructions, see the Integration documentation.

Setup

  1. Go to Sources in RunReveal
  2. Click the Netskope source tile
  3. Give it a name and click Connect Source
  4. Fill in the required fields with your Netskope API credentials

RunReveal will poll the Netskope API periodically to fetch new logs. Historical logs will be backfilled on first sync.

Schema

The following columns are exposed for this source. RunReveal applies schema normalization across all sources, ensuring uniform field names and data types for cross-source queries and reusable detection logic.

Table: netskope_logs (69 columns)

ColumnType
workspaceIDString
sourceIDString
sourceTypeString
sourceTTLUInt32
receivedAtDateTime
idString
eventTimeDateTime
eventNameString
eventIDString
srcIPString
srcASCountryCodeString
srcASNumberUInt32
srcASOrganizationString
srcCityString
srcConnectionTypeString
srcISPString
srcLatitudeFloat64
srcLongitudeFloat64
srcUserTypeString
dstIPString
dstASCountryCodeString
dstASNumberUInt32
dstASOrganizationString
dstCityString
dstConnectionTypeString
dstISPString
dstLatitudeFloat64
dstLongitudeFloat64
dstUserTypeString
actorMap(String, String)
tagsMap(String, String)
resourcesArray(String)
serviceNameString
enrichmentsArray(Tuple(data Map(String, String), name String, provider String, type String, value String))
readOnlyBool
ColumnType
rawLogString
netskopeEventIDString
timestampUInt64
eventTypeString
userString
appString
activityString
alertTypeString
severityString
policyString
deviceString
locationString
categoryString
cclString
cciUInt32
accessMethodString
trafficTypeString
protocolString
urlString
pageString
objectString
objectTypeString
instanceIDString
fromUserString
toUserString
fileTypeString
fileNameString
fileSizeUInt64
dlpProfileString
dlpRuleString
browserSessionIDString
connectionIDString
requestIDString
transactionIDString