Version 4.5.0
- Added a “Netskope DEM” dashboard providing visibility into Digital Experience Monitoring (DEM) data.
- Added a
demquerycustom search command that fetches DEM data (RUM, HTTP, and Traceroute sources) directly from the Netskope API for use in the new dashboard and ad-hoc searches. - Fixed a character encoding issue in the “Events (Multi Iterator)” input by explicitly decoding API responses as UTF-8 preventing corruption of non-ASCII characters.
Version 4.4.0
- Added support for Netskope Log Streaming (NLS) sourcetypes with CSV parsing.
- Added comprehensive CIM field mappings for all NLS sourcetypes to maintain compatibility with Splunk Enterprise Security.
Version 4.3.3
- Fixed field extraction issue for Web Transactions v2.
- Added UTF-8 encoding to ensure proper handling of characters in Multi Iterator input.
Version 4.3.2
- Included field parsing for data ingested from Splunk Cloud TAs under log streaming using sourcetype=netskope:webtransaction.
Version 4.3.1
- Fixed data duplication issue with Connection events.
Version 4.3.0
- Introduced a new “Events (Multi Iterator)” input option for the Application, Connection, and Network event types, enabling event collection in CSV format.
- Updated AoB to latest version (v4.5.0).
Version 4.2.0
- Refactored checkpoint management in the Netskope iterator to simplify state handling and improve reliability.
- Enabled persistence of subscription key and subscription path in Web Transactions v2.
Version 4.1.0
- Added Clients (Iterator) input.
- Added new Alert Types: Device and Content.
- Updated NetskopeSDK to v0.0.41.
Version 4.0.2
Updated Splunk SDK to v2.1.0.
Version 4.0.1
Fixed an issue where Web Transaction logs were not being collected due to invalid characters.
Version 4.0.0
- Added option to include/exclude specific fields in Alerts (iterator), Events (iterator), and Web Transactions V2 inputs
- Fixed the issue of multi-threading in iterator inputs.
- Enhance internal logs to include more details.
- Add a Troubleshooting section in the TA.
- Fixed other minor issues.
Version 3.7.3
- Updated Splunk Add-on builder version v4.2.0 to support cloud compatibility
- Added compatibility with Python 3.9.
Version 3.7.2
Minor Enhancements.
Version 3.7.1
Fixed data collection issue in Web Transactions v2
Version 3.7.0
Migrated AoB to latest version (v4.2.0).
Version 3.7.0
- Added support for ‘Endpoint’ event type in ‘Events (Iterator)’ input.
- Removed ‘Events (Deprecated)’ and ‘Alerts (Deprecated)’ input.
- Updated error handling logic for API response for ‘Web Transaction’ input.
- Added ‘WebTx’ postfix for ‘Web Transaction V2’ input user-agent.
- Upgraded Netskope SDK to 0.0.38.
Version 3.6.0
- Added “Email Notification” feature that will send an Email if Input(s) is/are inactive for a specified duration. This feature can be enabled from the “Configuration” Page.
- Added support of proxy for “Web Transaction V2” input validation.
- Changed the default value of the “action” field to “NA” for the Connection/Page event.
Version 3.5.0
- Added ‘Netskope Quarantine File’ Alert Action, to move malware alert file to the destination container and create an empty file with ‘tombstone_’ prefix in the source container.
- Added ‘Storage Account’ tab in the ‘Configuration’ page to configure Azure storage account details.

