Netskope Help

Elastic Plugin for Log Shipper

This document explains how to configure your Elastic integration with the Log Shipper module of the Netskope Cloud Exchange platform. This integration allows pushing alerts and events from Netskope to the Elastic platform.

Requirements

To complete this configuration, you need:

  • A Netskope tenant (or multiple, for example, production and development/test instances)

  • A Netskope Cloud Exchange tenant with the Log Shipper module already configured.

  • Your Filebeat TCP Server address and port.

Note

Verify your Elastic instance permissions are secure and not set up for open public access. Only allow access to your cloud storage instance from your Cloud Exchange Host and any other addresses that need access.

Workflow
  1. Configure Filebeat to listen on a specific port.

  2. Configure the Elastic plugin.

  3. Configure Log Shipper Business Rules for Elastic.

  4. Configure Log Shipper SIEM Mappings for Elastic.

  5. Validate the Elastic plugin.

Click play to watch a video.

 
  1. Go to Settings > Plugins.

  2. Select the Elastic box to open the plugin creation dialog.

  3. Enter a Configuration Name.

  4. Select a valid Mapping (Default Mappings for all plugins are available). Click Next

    image1.png
  5. Enter your Server Address and Server Port.

    image2.png
  6. Click Save.

    image3.png
  1. Go to Log Shipper > Business Rules.

    image4.png
  2. Click Create New Rule.

    image5.png
  3. Enter a Rule Name and select the filters to use.

  4. Click Save.

    image6.png
  1. Go to Log Shipper > SIEM Mappings and click Add SIEM Mapping.

  2. Select a Source Configuration, Business Rule, and Destination Configuration.

    image7.png
  3. Click Save.

To validate the plugin workflow, you can check from Netskope Cloud Exchange and from Kibana.

To validate from Netskope Cloud Exchange, go to Logging.

image8.png

To validate from the Kibana.

  1. Open your Kibana instance to view data.

    image9.png
  2. Log in.

    image10.png
  3. Click Discover from the left panel.

    image11.png
  4. Click logs-*.

    image12.png
  5. Select filebeat-* from the dropdown.

    image13.png
  6. Set a time range and click Refresh to see data.

    image14.png