Endpoint Events Data Collection and Dashboard

Endpoint Events Data Collection and Dashboard

This feature may require additional licensing. Contact your Netskope Sales and Support team to enable this in your account.

The Endpoint Events data collection and dashboard are available in the Netskope Library. Navigate to Advanced Analytics > Explore > Data Collection > Endpoint Events to access the dashboard.

Admins can gain insight from endpoint events in Netskope Advanced Analytics (NAA) through out-of-the-box reports / dashboards, and customizable reporting options using 70+ data attributes.

Benefits include:

  • Comprehensive insight into user actions and behaviors
  • Flexibility to create reports that meet specific business needs

Prerequisites

  • Your account must have Endpoint DLP enabled in order to generate / populate data for your dashboard.
  • You account must have NAA enabled (trial or license) to access the data collection and dashboard.

Endpoint Events Dashboard

This dashboard shows general information and trends over time for endpoint alerts and files transferred by file size. In addition you can quickly see the number of users, devices, and triggered alerts. The default event date time is the last seven days.

User Insights

The Users dashboard tracks top users triggering alerts, including DLP profiles, and actions taken.

Data Analysis

This dashboard monitors DLP profiles and rules triggered, along with file types, file size, and actions taken.

Device Breakdown

This dashboard provides a detailed analysis by device type (USB, printer, network share), including file types, sizes, and actions.

Endpoint Event Data Fields

FIELD NAMECATEGORYDESCRIPTIONTYPE
Access MethodDimensionThis field shows the actual access method that triggered the event.String
ActionDimensionAction that triggered the event.String
ActivityDimensionActivity performed by the user, e.g. copy, move, save.String
Alert (Yes / No)DimensionIndicates whether alert is generated or not. Populated as yes for all alerts.Yes/No
Alert NameDimensionName of the alert / action that is triggered.String
Content Process IDDimensionString
Content Process NameDimensionString
Content Process pathDimensionString
DLP Incident IDDimensionIncident ID associated with sub file. For example a zip file, this is the incident ID for files within the zip file.String
DLP ProfileDimensionDLP profile that triggered the event (Alerts page).String
DLP RuleDimensionDLP rule name.String
Destination File DirectoryDimensionContent file directory details.String
Destination File NameDimensionContent file name.String
Destination File PathDimensionContent file path details.String
Device IDDimensionUSB device ID.String
Device NameDimensionDevice name for the USB.String
DriverDimensionPrinter driver provided by printer manufacture.String
Enforced Policy NameDimensionPolicy that triggered the event.String
Event DateDimensionTimestamp when the event/alert occured.Date date
Event Day of MonthDimensionTimestamp when the event/alert occurred.Date day of month
Event Day of WeekDimensionTimestamp when the event/alert occurred.Date day of week
Event Day of Week IndexDimensionTimestamp when the event/alert occurred.Date day of week index
Event Day of YearDimensionTimestamp when the event/alert occurred.Date day of year
Event HourDimensionTimestamp when the event/alert occurred.Date hour
Event Hour of DayDimensionTimestamp when the event/alert occurred.Date hour of day
Event Minute5DimensionTimestamp when the event/alert occurred.Date minute5
Event MonthDimensionTimestamp when the event/alert occurred.Date month
Event Month NameDimensionTimestamp when the event/alert occurred.Date month name
Event Month NumDimensionTimestamp when the event/alert occurred.Date month num
Event Month of QuarterDimensionTimestamp when the event/alert occurred.String
Event QuarterDimensionTimestamp when the event/alert occurred.Date quarter
Event TimestampDimensionTimestamp when the event/alert occurred.Date time
Event TypeDimensionLists the device control events or content control events.String
Event WeekDimensionTimestamp when the event/alert occurred.Date week
Event Week of YearDimensionTimestamp when the event/alert occurred.Date week of year
Event YearDimensionTimestamp when the event/alert occurred.Date year
Executable HashDimensionExecutable hash.String
Executable Signed (Y/N) (Yes / No)DimensionExecutable Signed (Y/N).Yes/No
File OriginDimensionContent file origin details.String
File SHA256DimensionContent sha256 for the file.String
File SizeDimensionSize of the file in bytes.Number
File TypeDimensionTrue file type.String
Hardware Device TypeDimensionUSB device type.String
HostnameDimensionHostname.String
LocationDimensionIP address, URL, or human-readable address.String
MD5DimensionContent MD5 hash of the file.String
OSDimensionEndpoint host Operating System.String
OS DetailsDimensionEndpoint host Operating System details.String
OS UsernameDimensionName of the user being used on the OS.String
Organization UnitDimensionString
Policy NameDimensionName of the policy configured by admin. This is the policy that should have triggered.String
PortDimensionName of printer config port on windows.String
Printer TypeDimensionType of printer (i.e. Network Printer, Local Printer).String
Process Certificate SubjectDimensionSubject from certificate, identifying what app triggered event.String
Product IDDimensionUSB product ID.String
Serial NumberDimensionSerial number of the USB.String
UNC PathDimensionIdentifier for printer, printer address.String
User GroupDimensionUser group for which the event correlates. This ties to user information extracted from Active Directory using the AD Importer / Connector application.String
UsernameDimensionUser email.String
Vendor IDDimensionUSB Vendor ID .String
AlertsMeasureCount
DevicesMeasureThe unique count of devices by USB device ID.Count distinct
EventsMeasureSum
FilesMeasureUnique count of files transferred that hit a policy.Count distinct
PolicyMeasureUnique count of policy name.Count distinct
UsersMeasureUnique count of users by user email.Count distinct
Event DateMeasureDate time
Event DateMeasureDate time
File SizeMeasureSum
Measures Sum - File Size (GB)MeasureSum
Measures Sum - File Size (KB)MeasureSum
Measures Sum - File Size (MB)MeasureSum
Share this Doc

Endpoint Events Data Collection and Dashboard

Or copy link

In this topic ...