Netskope Help

Configure the Netskope Plugin for Log Shipper

You will need your Netskope tenant name and API token (V1, and optionally V2) to complete this configuration.

  1. Log in to your Cloud Exchange tenant.

  2. Go to Settings and click Netskope Tenants.

  3. Click Add Tenant.

  4. Enter a Log Shipper name for your Netskope tenant.

  5. Enter your Netskope tenant name. Do not enter the <tenant_name>, URL. Enter just your tenant. For example, if it's, just enter mycompany. If your tenant has eu in the URL, enter

  6. Enter your Netskope tenant API token(s) obtained previously.

  7. Set the range for ingesting data from Netskope. In this case, set the Initial Range to 7 days to pre-populate Log Shipper.

  8. If you use a proxy, enable the proxy toggle.

  9. Click Save. Your tenant appears on the page.

  10. Now configure the Netskope plugin for Log Shipper. Go to Settings > Plugins.

  11. Select the Netskope (CLS) box to open the plugin creation pages. Field descriptions are provided here.

    Enter and select the Basic Information on the first page:

    • Configuration Name: Enter a name appropriate for your integration.

    • Tenant: Choose the Tenant you added previously.

  12. Click Next.

  13. Enter and select the Configuration Parameters on the second page:

    • Alert Type: Remove any alert types that you don't want to fetch.

    • Event Type: Remove any event types that you don't want to fetch.

    • Initial Range: Enter the number of hours to pull the data for the initial run.

  14. Click Save in the top right. Go to Threat Exchange > Plugins to see your new Netskope plugin.

Log Shipper Field Descriptions



Default Value

Configuration Name

Name of the Log Shipper plugin.


Tenant Name

Netskope Tenant name. For <companyname>, enter <companyname>.


Alert Type

Specifies all the alerts to pull from Netskope.


Event Type

Specifies all the events to pull from Netskope.


Initial Range

Enable/Disable polling data from Netskope.