Advanced Analytics Incidents Event Fields

Advanced Analytics Incidents Event Fields

The following table lists the Netskope Advanced Analytics Incidents event field names. This list is dynamic and may not contain each available field.

AA Incident NameDescriptionCategoryField Group
AssigneeAssignee nameDimensionDLP
Assignee Last UpdateTimestamp of when the assignee was last updatedDimensionDLP
AttachmentName of the attachment being sent through mailDimensionFile
BCCField to search events based on users in the bcc fieldDimensionGeneral
CCField to search events based on users in the cc fieldDimensionGeneral
DLP ActionSearch events based on a specific DLP profile actionDimensionDLP
DLP Fingerprint ClassificationSearch events for the DLP fingerprint classification within the profile that matches the contentDimensionFile
DLP Fingerprint MatchSearch events for the DLP fingerprint file within the profile that matches the contentDimensionFile
DLP Fingerprint ScoreSearch events for the DLP fingerprint score within the profile that matches the contentDimensionFile
DLP Incident StatusStatus of the DLP incident (e.g. New, In Progress, Closed)DimensionDLP
DLP Incident Status Last UpdateDLP incident status last updated timestampDimensionDLP
DLP Severity StatusStatus of DLP incident severityDimensionDLP
DLP Severity Status Last UpdateDLP incident severity last updated timestampDimensionDLP
Email SubjectSearch events based on the email subjectDimensionGeneral
Incident IDIncident Unique IdentifierDimensionGeneral
Incident TypeType of incident includes: DLP, UEBA, Compromised Credentials, Malware, Malsite.DimensionGeneral
Malsite Destination CountryDestination country of the malicious siteDimensionMalsite
Malsite Destination RegionDestination region of the malicious siteDimensionMalsite
Malsite First SeenMalsite first seen dateDimensionMalsite
Malsite Last SeenMalsite last seen dateDimensionMalsite
Transaction IDType of log messageDimensionGeneral

Tip

To see specific alerts associated with each incident, use the ‘Merged Query’ feature and merge with the alerts table using the ‘Incident ID’ or ‘DLP Incident ID’ (DLP alerts only) fields.

Enriched Fields

The data fields below are enriched from the data in the Alerts data collection. Use these enriched fields coupled with the “Merged Query’ to view targeted details of your DLP incident.

  • Access Method
  • Activity
  • Application
  • Application Activity
  • Attachment
  • Browser
  • CCL
  • Connection ID
  • Destination Country
  • Destination IP
  • Destination Location
  • Destination Region
  • Destination Timezone
  • Destination Zipcode
  • Device Classification
  • Device Type
  • DLP File Name
  • DLP Fingerprint Classification
  • DLP Fingerprint Match
  • DLP Fingerprint Score
  • DLP Incident ID
  • DLP is Unique Count
  • DLP Parent ID
  • DLP Profile
  • DLP Rule
  • DLP Rule Count
  • DLP Rule Severity
  • Event Timestamp
  • Exposure
  • External Collaborator Count
  • File ID
  • File Language
  • File Owner
  • File Path
  • File Size
  • File Type
  • From User
  • Hostname
  • Instance ID
  • Internal Collaborator Count
  • MD5
  • MIME Type
  • Object
  • Object ID
  • Object Type
  • Original File Path
  • OS
  • OS Version
  • Referrer
  • Request ID
  • Session ID
  • Shared With
  • Shared With Domains
  • Site
  • Source Country
  • Source IP
  • Source Location
  • Source Region
  • Source Zipcode
  • Telemetry App
  • To User
  • Total Collaborator Count
  • Transaction ID
  • URL
  • User
  • User IP
Share this Doc

Advanced Analytics Incidents Event Fields

Or copy link

In this topic ...