The Custom Attributes Enrichment feature allows you to integrate internal user data—such as job title, department, or country—directly with Netskope event data. Once imported, these attributes function as native data attributes within the platform, enabling advanced filtering, custom expressions, and deep visualization in Advanced Analytics and Skope IT. This enrichment is supported across a wide range of data collections, including Page Events, Application Events, Alerts, Cloud Firewall (CFW), and Endpoint Events.
Prevent Field Name Collisions
To prevent field name collisions with Netskope’s existing schema, avoid using custom attribute names that are the same as existing event fields (for example, title or policy). This can result in incorrect values appearing in events. Instead, use unique, descriptive names for custom attributes (for example, custom_ad_title instead of title).
For Advanced Analytics you can use these custom attributes for:
-
Filtering and Visualization
-
Custom Expressions
-
Table Calculations and Aggregation
For Skope IT you can use these custom attributes for:
-
Filtering
-
Custom querying
Supported Data Collections
Custom attribute enrichment is supported for the following event types in both Advanced Analytics and Skope IT:
-
Page Events
-
Application Events
-
Alerts
-
CFW Events (Cloud Firewall)
-
Network Events (NPA)
-
Endpoint Events
Data Flow
| Data Flow | Timeframe | Description |
|---|---|---|
| User Imports to Event Data | Approximately 1 day | Custom attributes are pushed to the user attributes collection and subsequently to the event data. |
| Enrichment in Event Pipeline | Real-time (at the time of event) | Enrichment occurs when the event is processed, using the attribute values available at that moment. |
| Data Visibility in Netskope Advanced Analytics | After event processing and pipeline updates (Approx. 1 day for NAA) | Once the enriched data is available in the cloud database, it can be queried by NAA. |
Behavioral Characteristics
Enrichment Window
-
Enrichment is a point-in-time process, associated with the event timestamp.
-
Any changes to custom attributes (updates or deletions) are NOT applied retroactively to events that have already been enriched. They only apply to new events generated after the change.
Attribute Changes and Removal
Updating Attributes: Changes schema specification (e.g., via SCIM API or provisioning). New enrichment uses the updated schema; historical events are not modified.
Deleting/Disabling Attributes: Request/Disable the attribute via the user interface or API. The attribute is removed from the provisioning/pipeline flow. For existing enriched historical events, the value will remain/display for Skope IT. For NAA the value displays as null if the user is no longer being used.
Deletion of Data: For NAA, if a user is no longer being used, the associated custom attribute values for past events will be displayed as null.

