Skip to main content

Netskope Help

Configure the Netskope Plugin for Log Shipper

This document explains how to configure the Cloud Exchange integration with the Log Shipper module of the Netskope Cloud Exchange platform.

Prerequisites

To complete this configuration, you need:

  • A Netskope Tenant (or multiple, for example, production and development/test instances) that is already configured in Cloud Exchange.

  • A Netskope Cloud Exchange tenant with the Log Shipper module already configured.

Workflow
  1. Configure the Netskope plugin for Log Shipper.

  2. Configure Log Shipper Business Rules and SIEM mappings.

  3. Validate the Netskope plugin for Log Shipper.

  1. In Cloud Exchange, go to Settings and click Plugins

  2. Select the Netskope (CLS) box to open the plugin creation page.

  3. Enter a Configuration Name.

  4. Select your Tenant from the dropdown.

    image6.png
  5. Click Next.

    image8.png
  6. Choose Alert Types. (This will filter alerts based on types you select.)

    Note

    This filter will not be applied if you have an Alert filter at the Tenant level starting with v4.1.0. In this case, the filter at the Tenant level will override this filter setting.

  7. Choose Event Types. (This will filter events based on types you select.)

  8. Number of days to pull the data for initial run.

  9. Click Save.

    image3.png
  1. In Log Shipper, go to Business Rules.

  2. Click Create New Rule.

    image7.png
  3. Enter a Rule Name and build the appropriate filter query condition on the field(s) for the business rule. You can also type the query manually by pressing the Filter Query button.

    image2.png
  4. Click the Save button.

  1. In Log Shipper, go to SIM Mappings.

  2. Click Add SIEM Mappings.

    image5.png
  3. Click the Business Rule dropdown and choose the Business rule you created previously.

  4. Select the Source and Destination Configuration dropdown between which the SIEM mapping will be configured based in selected Business Rule.

    image4.png
  5. Click Save.

To verify the plugin is working correctly, go to LogShipper > SIEM Mappings, confirm that the proper count of the logs are sent under Total Logs Sent column for the configured SIEM Mapping

image1.png
WebTx Plugin Field Descriptions

Field

Description

Configuration Name

Name of the WebTx plugin.

Service Account JSON

Specifies the Events Streaming Subscription Key from your Netskope tenant.

Subscription Path

Specifies the Events Streaming Subscription Endpoint from your Netskope tenant.