The Netskope pack for Cribl offers log parsing and normalization for Netskope’s WebTx logs that are generated and placed into cloud storage containers (Netskope Log Streaming) by Intelligent Security Services Edge (SSE) components. The Netskope events are usually captured using a Cribl Stream Rest Collector whose config is maintained in the Cribl REST Collector Repository.
Cribl’s pack retrieves web transaction data for the purpose of integrating this rich context into security analytics systems or for long-term compliance needs. Functionality within the packs dropping or reducing the data. Post setting up the stream to the cloud bucket, this pack can be used to ensure appropriate streaming to Cribl.
- Streamtags: Netskope
- Use Cases: Reduction, Routing, Filtering
- Data Type: Events/Logs
Deployment
- Post ensuring integration set up to the Cloud Storage bucket from Log Streaming, install this pack from the Cribl Pack Dispensary.
- Configure a Cloud Storage Collector for your source. For example: S3 or Azure Blob source collectors.
- Create a Route and filter based on your source. For example, my source is named Netskope-Log-Streaming-Events-Alerts. You will need to match the name of your source.
- Select the cc-netskope-log-streaming-events-and-alerts pack as the pipeline.

