Loading

Netskope

<div class="condensed-table">
| | |
| --- | --- |
| Version | 1.22.0 (View all) |
| Compatible Kibana version(s) | 8.13.0 or higher |
| Supported Serverless project types
What’s this? | Security
Observability |
| Subscription level
What’s this? | Basic |
| Level of support
What’s this? | Elastic |

</div>
This integration is for Netskope. It can be used to receive logs sent by Netskope Cloud Log Shipper on respective TCP ports.

The log message is expected to be in JSON format. The data is mapped to ECS fields where applicable and the remaining fields are written under netskope.<data-stream-name>.*.

  1. Configure this integration with the TCP input in Kibana.

  2. For all Netskope Cloud Exchange configurations refer to the Log Shipper.

  3. In Netskope Cloud Exchange please enable Log Shipper, add your Netskope Tenant.

  4. Configure input connectors:

    1. First with all Event types, and
    2. Second with all Alerts type. For detailed steps refer to Configure the Netskope Plugin for Log Shipper.
  5. Configure output connectors:

    1. Navigate to Settings → Plugins.
    2. Add separate output connector Elastic CLS for both Alerts and Events and select mapping "Elastic Default Mappings (Recommended)" for both.
  6. Create business rules:

    1. Navigate to Home Page > Log Shipper > Business Rules.
    2. Create business rules with Netskope Alerts.
    3. Create business rules with Netskope Events. For detailed steps refer to Manage Log Shipper Business Rules.
  7. Adding SIEM mappings:

    1. Navigate to Home Page > Log Shipper > SIEM Mappings

    2. Add SIEM mapping for events:

      • Add Rule put rule created in step 6.
      • Add Source Configuration put input created for Events in step 4.
      • Add Destination Configuration, put output created for Events in step 5.
Note

For detailed steps refer to Configure Log Shipper SIEM Mappings. Please make sure to use the given response formats.

This package has been tested against Netskope version 95.1.0.645 and Netskope Cloud Exchange version 3.4.0.

Default port: 9020

Default port: 9021