Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    User Provisioning and Authentication
    SCIM User Provisioning with RBACv3
    Custom Attributes Enrichment

    Custom Attributes Enrichment

    The Custom Attributes Enrichment feature allows you to integrate internal user data—such as job title, department, or country—directly with Netskope event data. Once imported, these attributes function as native data attributes within the platform, enabling advanced filtering, custom expressions, and deep visualization in Advanced Analytics and Skope IT. This enrichment is supported across a wide range of data collections, including Page Events, Application Events, Alerts, Cloud Firewall (CFW), and Endpoint Events.

    This feature requires additional licensing. Contact your Netskope Support or Sales team to enable it in your account.

    Prevent Field Name Collisions

    To prevent field name collisions with Netskope’s existing schema, avoid using custom attribute names that are the same as existing event fields (for example, title or policy). This can result in incorrect values appearing in events. Instead, use unique, descriptive names for custom attributes (for example, custom_ad_title instead of title).

    For Advanced Analytics you can use these custom attributes for:

    • Filtering and Visualization

    • Custom Expressions

    • Table Calculations and Aggregation

    For Skope IT you can use these custom attributes for:

    • Filtering

    • Custom querying

    Supported Data Collections

    Custom attribute enrichment is supported for the following event types in both Advanced Analytics and Skope IT:

    • Page Events

    • Application Events

    • Alerts

    • CFW Events (Cloud Firewall)

    • Network Events (NPA)

    • Endpoint Events

    Data Flow

    Data FlowTimeframeDescription
    User Imports to Event DataApproximately 1 dayCustom attributes are pushed to the user attributes collection and subsequently to the event data.
    Enrichment in Event PipelineReal-time (at the time of event)Enrichment occurs when the event is processed, using the attribute values available at that moment.
    Data Visibility in Netskope Advanced AnalyticsAfter event processing and pipeline updates (Approx. 1 day for NAA)Once the enriched data is available in the cloud database, it can be queried by NAA.

    Behavioral Characteristics

    Enrichment Window

    • Enrichment is a point-in-time process, associated with the event timestamp.

    • Any changes to custom attributes (updates or deletions) are NOT applied retroactively to events that have already been enriched. They only apply to new events generated after the change.

    Attribute Changes and Removal

    Updating Attributes: Changes schema specification (e.g., via SCIM API or provisioning). New enrichment uses the updated schema; historical events are not modified.

    Deleting/Disabling Attributes: Request/Disable the attribute via the user interface or API. The attribute is removed from the provisioning/pipeline flow. For existing enriched historical events, the value will remain/display for Skope IT. For NAA the value displays as null if the user is no longer being used.

    Deletion of Data: For NAA, if a user is no longer being used, the associated custom attribute values for past events will be displayed as null.

    In this Topic
    • Custom Attributes Enrichment