If you're having trouble at any stage please contact us at firstname.lastname@example.org.
Netskope security platform provides deep visibility into cloud and web transactions so users can make informed policy decisions to reduce risk. The platform enables enterprises to secure both sanctioned and unsanctioned cloud services, protect sensitive data across the cloud and web, and stop the most advanced online threats.
For more information on Netskope please visit:
The main challenges and needs are to:
- Get and retain full audit of activities in Netskope cloud accounts.
- Get all alerts and policy events from Netskope cloud
- The granular activities and alerts should be available at the organization’s central log or event management system for compliance, investigation or forensic needs.
- Detect security threats and policy violations
What is it
SkyFormation for Netskope Cloud Connector, is part of the SkyFormation Collect (c) module.
It continuously retrieves audit events from the different audit sources in the Netskope cloud account, unifies the events into a common application events format, enrich the events with needed detection context and send the events to any existing SIEM/SOC system.
How it works
SkyFormation for Netskope Cloud Connector retrieves the events from the Netskope service through its APIs. Before sending the events to the existing SIEM/SOC system the connector will
- Unify the events into the SkyFormation unified application events format
- Embed the origin event into the SkyFormation event as a blob
- Parse the origin event into a set of dedicated key-value fields
- Enrich the event with detection context (e.g. AD identity information)
- Encode the resulted event into the target SIEM/SOC system standard format (e.g. CEF)
- Send the event to the existing SIEM/SOC system over syslog
Connector's API/Audit Sources & Events Supported
|Audit Source (API)||Service/Module Covered||Event Included|
|Events||audit, page, application, infrastructure||All|
How to on-board Netskope Connector to SkyFormation app