Netskope Cloud Exchange

Configure SIEM Mappings for Log Shipper

Admins can configure SIEM mappings to ingest the events and alerts from a Netskope tenant into their SIEM platform. Admin should configure Netskope and SIEM destination plugin, and also configure a business rule if they plan to ingest only selective alerts/events.

  1. Go to Log Shipper > SIEM Mappings.

    image33.png
  2. Click Add SIEM Mapping.

  3. Select a Source Configuration, Business Rule, and a Destination Configuration.

    image34.png
  4. Click Save.

Now all the incoming alerts/events should be ingested into your destination configuration.