How quickly is my configuration change applied?
Any change on streamingclient API configuration is synchronized to clients in two minutes. However, Log Streaming initialization can take up to one hour and Log Streaming configuration changes can take up to 15 minutes.
How can I verify that my configuration is complete?
Check the following:
- Log streaming is configured to “streamingclient” with correct Destination ID
- Destination ID is enabled, with enabled targets
- Client ID defines is Destination targets are enabled
Finally, verify the logs on the Event Streaming Client
How does High Availability work?
- Cloud Architecture managed by Netskope is fully redundant with multiple nodes and multiple Internal links. Once initialized, the Cloud Infrastructure retain up to 24 hours if no SIEM can be reached
- It is recommended to deploy 2 or more Event Client Streaming nodes to ensure high availability on the Customer side. All clients are receiving events in parallel.
- Best practice, it is recommended to have two or more syslog targets for each Event Client Streaming nodes using syslog TCP.
For more details, review Event Streaming Client Architecture.
I have multiple tenants, how should I deploy Event Streaming Client?
Only one Event Streaming Client per host is currently supported. A different Linux host is required to streaming events from another server.
Does Event Streaming Client support HTTP Proxy?
Yes, HTTP Proxy support has been released. Please make sure the latest version of installation script is used to configure it.
Is port 50051 mandatory?
Yes, this port is used to download events.

