Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Data Loss Prevention
    Data Lineage
    Supported Activities and Event Sources

    Supported Activities and Event Sources

    Data Lineage builds its graph from activity that other Netskope services already capture. This page lists what each source contributes, so you can tell what a graph is built from and what enabling an additional source would add.

    Data Lineage draws on two sources:

    • Real-time Inline Protection

    • CASB API Data Protection

    Each sees a different part of a file’s journey, and they overlap deliberately. A file downloaded from a managed cloud application, edited or rename locally and copied to a USB drive is only fully traceable when inline and endpoint are both in place.

    Real-time Inline Protection Activity

    Real-time Inline Protection coverage comes from traffic steered to Netskope, whether through the Netskope Client, IPSec, GRE, an explicit or local proxy, a mobile profile, or reverse proxy. It’s the broadest source; it sees activity in any application a user reaches through the browser, including applications you have not sanctioned and do not manage.

    Activities captured inline include: Create, Edit, Upload, Download, Copy, Move, Rename, Share, and Send (webmail attachments in Gmail and Outlook).

    Inline is the only source that sees unsanctioned and personal-instance destinations, which makes it the primary source for exfiltration paths.

    CASB API Data Protection Activity

    API Data Protection coverage comes from Netskope connecting directly to a sanctioned cloud application and reading activity from it. It sees things that never cross the network: a file shared from inside the application, an edit made in the web editor, a file moved between folders by another user. Both Next Generation API Data Protection and classic API-enabled Protection connectors feed Data Lineage.

    Activities captured through API Date Protection include: Create, Edit, Upload, Download, Copy, Move, Rename, Share, and Invite (shown as Share).

    API Date Protection also contributes scan results for files that existed before the connector was enabled, so those files have a starting point in the graph. It’s also the only source for applications that use certificate pinning in their desktop clients, where inline inspection is not possible.

    Activity that leaves the device (reported with Endpoint DLP):

    What Data Lineage Treats as a File

    Data Lineage tracks file objects: documents, spreadsheets, presentations, PDFs, images, media, archives, and mail attachments. Chat messages, calendar entries, database records, and other non-file objects are outside scope.

    Activity Coverage Varies by Application

    Not every application reports every activity, and some report an activity under the wrong name. A few patterns are worth knowing. Some applications report a Copy as an Edit or a Create, and a Move as a Rename. Data Lineage corrects this for applications where the behavior is known and consistent, including OneDrive, SharePoint, Google Drive, Box, Dropbox, Gmail, and Outlook.

    Some applications report a Share without enough file information to attach it to the right file, so the share appears without a connection to its file.

    Desktop clients that use certificate pinning, including the Google Drive and Dropbox desktop applications, cannot be inspected inline. Activity through those clients is visible only through API Data Protection or Endpoint DLP.

    Applications that serve files from the browser cache, such as Figma, may report a download without a usable filename. Attachments sent through the SMTP proxy or a desktop Outlook client are not currently traceable.

    In this Topic
    • Supported Activities and Event Sources