Event Streaming Client provides a high performance and centrally managed solution to stream Transaction Events to a SIEM.
This page provides an overview and references to other sections.
To learn more:
- Event Streaming Client Architecture
- Event Streaming Client Requirements
- Event Streaming Client Deployment
- Event Streaming Client Configuration
- Event Streaming Client Operations and Troubleshooting
- Event Streaming Client FAQs
Supported features
- Events generated by Netskope Proxy are forwarded to the SIEM via syslog in less than five minutes
- Active/Active Event Streaming Clients to Active/Active SIEM
- Transaction events only, up to format 4
- Syslog TCP and UDP (TCP recommended to ensure no event is lost)
- Customizable Syslog Header
- Event format: JSON, CEF, ELFF
- Customizable field selection:
- Field selection with ordering
- Field rename
- Default value
- Remove empty fields
- HTTP proxy support for internet access
- Weekly auto upgrade
- All configuration is done via API to the cloud management, UI in the management console will be delivered in a second phase
- Processing metrics available on the host. Metrics are collected centrally but are not yet exposed in the central console.
Known Limitations
- FedRamp/PBMM environments are not yet supported
- Multiple tenants on the same host are not yet supported

