Metric Details

About the Metric Details Section
The metric details section provides you with metric details for monitored SaaS and private applications. Metrics can be viewed by clicking on the SaaS application and private application tabs based on your troubleshooting needs.
SaaS/Custom Application Tab
These metrics provide you with data on monitored SaaS applications. The following metrics can be viewed by clicking the SaaS/Custom Application tab:
- Connectivity to Netskope NewEdge
- Tunnel Latency – Overlay
- Network Path Latency – Underlay
- End-to-End Metrics
- Time to First Byte, Time to Last Byte
- Total Response Time
- Device Performance and Health Metrics
- CPU Usage
- Memory Usage
- Disk Usage
- Network Throughput
- Disk I/O Rate
- Battery
- Wifi Strength
- Network Events, Device Events
- Netskope Metrics
- Processing Time
- Application Metrics
- Round Trip Time
- TCP Connection Time, SSL Handshake Time
- Server Response Time
Private Application Tab
The Private Application tab provides the following metrics:
- Network Path View
- Path Segment Metrics
- Publisher Utilization Metrics
- Publisher CPU Usage
- Publisher Memory Usage
- Publisher Storage Usage
- Device Performance and Health Metrics
- CPU Usage
- Memory Usage
- Disk Usage
- Network Throughput
- Disk I/O Rate
- Battery
- Wifi Strength
- Network Events, Device Events
SaaS Application Metrics

The SaaS application metrics provide you with data on SaaS applications. You can select an application from the application cards in the Monitored Applications section to view metrics for a specific application. To learn more, please see Application Cards.
Connectivity to Netskope NewEdge
Tunnel Latency – Overlay

This metric displays the latency within the tunnel between the user’s device and the POP over a selected time range. Latency is measured by sending probes every 30 seconds. The final latency values shown in the chart are based on aggregated probe results. The aggregation depends on the polling frequency configured in the system settings. If the polling frequency is set to 5 minutes, all probe results collected within each 5-minute window are aggregated to compute the latency for that window.
In addition, the Overlay represents the mean of multiple measurements collected over a time duration specified in the DEM configuration, whereas the Underlay data reflects a single measurement taken at a specific point in time.
Therefore, occasional large discrepancies between these two metrics are not a concern. However, if a consistently large gap is observed, further investigation is warranted to understand the underlying cause.
Network Path Latency – Underlay (E2E)
This metric tracks the round-trip time (RTT) between a user’s client and a Netskope POP over the page’s selected time range measured via Traceroute.

The line chart provides several key behaviors and workflows:
- Trend Analysis: The interface displays RTT between the user’s device and netskope POP measured via Traceroute as a time series so you can easily observe performance trends over time rather than isolated measurements.
- POP Identity: Hover over any data point to view the connected POP, timestamp, RTT, and public IP address.
- Synchronized Zooming: The interface synchronizes chart behavior so that zooming into a time range in this chart simultaneously zooms the hop-by-hop view below.
- Path Analysis Transition: The tooltip includes a navigational shortcut where you can click View Hop-by-Hop to proceed to path-level analysis for the selected time window.
Network Path Latency – Underlay (Hop by Hop)

The network path visualization widget shows all network paths that were taken during the selected time period.The view aggregates all paths taken by the traceroute probes over the time period selected on the page filter into a unified hop by hop view. This view allows administrators to look at the ISP path taken to reach Netskope and its performance. The thickness of the path is determined by how many probes hit that path measured via traversal share. Traversal shares determine the likely hood of the path carrying users traffic.
Each node in the path corresponds to a router (or any network component delivering the routing service).
Each color identifies an AS (Autonomous System). In other words, this color identifies the ISP being traversed.
For each node, we identify its:
- location based on its RIR (Regional Internet Registry) registration
- AS name
- ISP name
For each node, we also provide the number of Network Probe tests that passed through it as well as its delay and packet loss.
Some consecutive nodes on a single path could be unknown. Instead of showing a line with multiple unknown nodes, they are grouped all together (hexagon icon).
The thickness of a link shows its usage. A thick line means that this path has been taken in a significant amount of Network Probe tests. On the other hand, a thin line means that the link has not been used much.
The graph is divided into three labeled sections:
- Internal Network: Hops discovered within the organization’s corporate network.
- Internet / ISP: Hops discovered across public internet infrastructure that are attributed to a specific ISP and ASN.
- Netskope Cloud: Netskope’s PoP..
Administrators can use the following interactive features to analyze path data:
- Time Slider with Location Awareness: Use the slider sitting above the hop-by-hop graph to filter the graph to a specific time segment. The slider tracks location context, meaning corporate site connections are colored and labeled with the site name, while remote connections are shown in blue and labeled Remote. Hovering over any segment displays the site name, the covered time window, and the number of probe samples collected. You can filter the view either by clicking a segment directly or by using the Site / Remote toggle switch.
- Edge (Link) Data: Hover over any edge (the line between two nodes) to see the link latency, traversal share, packet loss, and the Average, Median, and P95 latency for that hop. Edge thickness is proportional to traversal share, which makes dominant routes immediately visible.
- Traversal share is calculated as the percentage of probes that went through a link as compared to the total probes that were sent.
- Node Data: Hover over any node (router/hop) to view its IP address, traversal share percentage, and RTT to this node from the client measured via Traceroute probes. For internet-segment nodes, the tooltip also shows ISP, ASN, and geographic information. Nodes that did not respond to probes display a distinct visual indicator, and their tooltip shows the total count of unresponsive nodes at that position alongside their combined traversal share.
- Traversal share is calculated as the percentage of probes that went through a node as compared to the total probes that were sent.
- Latency Metric Selector: Use the metric toggle switch in the top right to change which latency value displays on the edge labels. You can choose between Average (arithmetic mean), Median (the midpoint value), and P95 (the 95th percentile representing near-worst-case conditions).
- ISP / ASN Legend: Review the dedicated legend panel to quickly identify the ISPs and Autonomous Systems present in the internet segment of the path, making it easy to attribute latency to specific network operators.
- Full-Screen Mode: Click the Full Screen button in the top right to expand the hop-by-hop view, which is especially useful for detailed analysis of paths with many hops or multiple parallel routes.
Total Connectivity Time

The Total Connectivity Time metric provides detailed information about the whole process of connecting the NSClient to the Netskope POP. You can hover over a data point on the chart to view information about the DNS resolution time, TCP Connection time, and TLS Handshake time.
This metric is only available for DEM Enterprise customers and app probes must be configured. To learn more, please see Digital Experience Management Enterprise and App Probes.
End-to-End Metrics
Time to First Byte, Time to Last Byte

The Time to First Byte (TTFB) corresponds to the time between the NSClient sending the HTTPS request (aka first byte of the request is sent) and when it receives the first byte of data payload (also called the response). The Time to Last Byte (TTLB) corresponds to the time between the NSClient sending the HTTPS request and when it receives the last byte of data payload.
This metric is only available for DEM Enterprise customers. To learn more about DEM Enterprise, please see Digital Experience Management Enterprise.
Total Response Time

The Total Response Time corresponds to the total duration of the App Probe test. It simulates the exact time for a transaction to complete.
Netskope Metrics
Processing Time

The Netskope Processing Time metric provides a measurement of the average time it takes for Netskope to process your traffic at any POP used by your organization. The data shows the average latency observed per minute, based on the traffic (including both requests and responses) processed at the last connected POP. The traffic for this measurement is selected through a process of random sampling each minute.
Transit Time

The Transit Time corresponds to the total time spent within the Netskope infrastructure. It includes the time spent in the NSProxy to forward the request from the NSClient to the application server, added to the time spent in the NSProxy to forward the response from the application server back to the NSClient.
Application Metrics
Round Trip Time

The observed Round Trip Time (RTT) for the user connecting through the connected Netskope POP to the monitored application.
TCP Connection Time, SSL Handshake Time

These metrics correspond to the time needed for the NSProxy to securely connect to the application server. This includes the TCP as well as SSL/TLS handshake processes. The Redirect count provides the number of redirections that have been observed during the select timeframe. The “Connection” time from the Netskope POPs to Applications section corresponds to the time spent by the NSProxy to establish a TCP connection with the targeted server. The “TLS” time from the Netskope POPs to Applications section corresponds to the time spent by the NSProxy to perform the TLS handshake process with the targeted server.
In case of redirections, this value corresponds to the sum of all occurrences during these redirections.
Server Response Time

The Server Response Time metric displays the time between the first byte of NSProxy request to the application server and the first byte of response received by the NSProxy. This Server time is the main server performance indicator, as it mainly takes the server processing time into account.
In case of redirections, this value corresponds to the sum of all occurrences during these redirections.
Private Application Metrics

The Private Application metrics provide you with data on performance of monitored private application hosts when used by a user.
Network Path

The Network Path view provides a view into all the paths taken by a user’s traffic to the monitored private application hosts and ports along with the performance of each path segment. Since DEM uses Real User Monitoring to measure performance of private applications, only monitored private applications used by the user in the selected time window are shown in this view. If a user has not used an application, the metrics will not show up on the page.
Network Path Node Categories

The following node categories are displayed in the Network Path metric:
- Device: The device of the selected user.
- Gateway: Netskope gateway that the user’s device was connected to. Netskope Client builds a TLS tunnel with the closest Client Gateway located in one of the several Netskope Data Centers. This is where policy is enforced.
- Stitcher: Publisher builds a TLS tunnel with the closest Publisher Gateway (Stitcher) located in one of the Netskope Data Centers. This is a gateway for the Publisher to connect to the Netskope Cloud.
- Publisher: Publisher nodes that were used to connect to private application hosts.
- App Host: Monitored private application hosts used by the user in the selected time window.
Vertices

Vertices connecting the nodes are represented as the path segments. You can hover over vertices for the following information:
- Sessions: This is the total count of sessions that went on this path segment in the selected timeframe.
- Latency: This is the observed average latency across all the sessions on the path segment.Hovering over the vertices will show you both Average and Median latency observed across all the user sessions that went to the path segment.
Policy Block View
Network Path View now highlights Explicit Policy Blocks when a user is unable to access a private application host due to a policy with the action set to Block. This helps admins instantly identify policy as the cause of access failure and degraded user experience.Once the user is unblocked, normal network path data for the application will appear. The Policy Block node will remain in the view to provide historical context.
Selecting a Unique Path to View Path Segment Metrics
Network Path Filters
You can use the Network Path metric filters to narrow down the number of unique paths shown in the widget. To learn more about Network Path filters, please see the Network Path Node Categories section.
About Filters

You can use the filters menu to view a network path by selecting from the following filter options:
- Gateways: Filters the path to only show selected gateways.
- Stitchers: Filters the path to only show selected stitchers.
- Publishers: Filters the path to only show selected gateways. Only the top 50 worst publishers are selected by default for performance reasons. You can deselect existing selections and select different publishers.
- Average Latency: Dynamically generates latency ranges based on AVG latency values across path segments and filters path segments to meet the selected latency thresholds.
- Policy Block: Filters the gateways where the policy block was observed.
To View a Unique Path
You can view a unique network path by selecting from the following options:
- Click on the nodes to select the path you would like to troubleshoot further.
- Alternatively, you can use the Network Path filter menu.
Path Segment Metrics
This section shows the performance metrics of individual path segments after a unique path has been selected from the Network Path view. This section will allow admins to correlate user experience issues to the selected segments. You can view the following Network Path Segments:
- Client to Gateway
- Gateway to Stitcher
- Stitcher to Publisher
Client to Gateway

Latency
Latency measures the delay in user’s application traffic between the client and the Gateway tunnel measured from the client. It is displayed as a time series, updated every minute to show how latency changes over time.
Latency is calculated as a running moving weighted average, which gives more importance to recent traffic measurements while smoothing out short-term fluctuations. This helps identify long-term network trends and potential performance issues.
Loss Rate
Packet loss is the percentage of data packets lost between the client and the Gateway. It is shown as a time series with 1-minute granularity.A high loss rate may indicate network congestion or issues, affecting reliability and performance.
Traffic
Traffic refers to the total amount of data (in bytes) uploaded and downloaded between the Client and the Gateway across all user connections in the past one minute.
Gateway to Stitcher

Latency
Latency refers to the measured delay in a user’s traffic between the Gateway and the Stitcher tunnel measured from the Gateway, plotted as a time series with 1-minute granularity. This is a measure of congestion in the Gateway to Stitcher tunnel which carried the user’s traffic.
Latency is calculated as a running moving weighted average, which gives more importance to recent measurement while smoothing out short-term fluctuations. This helps identify long-term network trends and potential performance issues.
Loss Rate
Loss rate is the rate of packet loss observed within the Gateway to Stitcher tunnel over the past minute.
It represents the percentage of NPA real user data packets that fail to reach the Stitcher.
Stitcher to Publisher

Latency
Latency refers to the measured delay in a user’s traffic between the Stitcher and the Publisher tunnel measured from the Stitcher, plotted as a time series with 1-minute granularity. This is a measure of congestion in the Stitcher to Publisher tunnel which carried the user’s traffic.
Latency is calculated as a running moving weighted average, which gives more importance to recent measurement while smoothing out short-term fluctuations. This helps identify long-term network trends and potential performance issues.
Loss Rate
The rate of packet loss observed within the Stitcher to Publisher tunnel over the past minute..
Sessions

You can view the session details to map the performance on the path segments (Client to Gateway, Gateway to Stitcher, or Stitcher to Publisher). To view the sessions for a user, please do the following:
- Hover a data point in a path segment metric.
- Click on the Sessions button.
- The Sessions window will open.
Sessions Windows

The Sessions Window provides detailed visibility into active user sessions for a selected user, time frame, and path segment. It also includes session close reasons to identify tunnel tear down by publisher disconnection.
The Sessions Window shows the following information:
- Time Range: The selected time window from the time series chart on the previous screen.
- User: The ID of the user being analyzed.
- Private App Host: The host of the private application accessed during the session.
- Private App: The name of the private application as defined by policy.
- Private App Port: The port(s) through which traffic was observed.
- Sessions: This table lists all sessions associated with the application host shown at the top of the screen.
- Start Time: When the session began.
- End Time: When the session ended.
- Port: The destination port used during the session.
- Total Traffic (RX/TX): Total download (RX) and upload (TX) traffic during the session.
- Session Close Reason: Reason the session ended. Possible values include:
- Dropped due to publisher disconnection
- Dropped based on policy
- Routine cleanup
Other Impacted Users

The “Other Impacted Users” metric helps you identify users who shared the same tunnel as the selected user during a period of latency degradation. You can view this metric by hovering over a data point in a Gateway to Sticher or Stitcher to Publisher metric, and clicking the “Other Impacted Users” button. This allows you to assess the potential scope of impact and optionally reach out to those users for confirmation or further investigation.
How to Filter
You can filter this view by selecting the available latency thresholds in the dropdown menu. The system will:
- Analyze the selected user’s tunnel paths within the path segments
- Identify tunnels where observed latency meets or exceeds the chosen threshold.
- Shows list of other users who had active connections for any DEM monitored private application hosts on those same tunnels during the selected time window.
Available Latency Thresholds
- ≥ 50 ms: Shows users who shared tunnels with latency of 50 ms or more.
- ≥ 100 ms: Shows users who shared tunnels with latency of 100 ms or more.
- ≥ 200 ms: Shows users who shared tunnels with latency of 200 ms or more.
Publisher Utilization Metrics

It shows CPU, memory, and storage usage over time for publishers the user used to access private apps. Monitor these to spot overloads, prevent performance issues, and ensure smooth app access.
Publisher CPU Usage
The percentage of processing capacity used by the publisher in the set time range for the selected user and device.
Publisher Memory Usage
The percentage of system memory in use in the set time range for the selected user and device.
Publisher Storage Usage
The percentage of allocated storage space consumed in the set time range for the selected user and device.
Device Performance and Health Metrics
CPU Usage

The CPU Usage metric displays the observed CPU Usage in the set time range for the selected user and device. You can hover over the time data points to view more detailed information about the CPU, processes, and threads. You can also click the View all processes button to view additional information, to learn more, please see the Process Info section.
Memory Usage

The Memory Usage metric displays the observed memory usage in the set time range for the selected user and device. You can hover over the time data points to view more detailed information about the memory, processes, and threads. You can also click the View all processes button to view additional information, to learn more, please see the Process Info section.
Disk Usage

The Disk Usage metric displays information about the disk usage of the selected user and device for the set time range. To view the disk usage percentage at a selected time, hover over the associated data point.
Process Info

The Process Info window provides you with additional details about the process info. To open the Process Info window for a specific timestamp, do the following:
- Select a set timestamp by hovering over the corresponding data point on the CPU Usage, Memory Usage, or Disk Usage metric.
- A box of data will appear when you hover over a timestamp.
- Click the View all processes button.
- The Process Info window will open.
- View information for the selected timestamp by clicking on the following tabs:
- CPU: This tab displays a list of the process, CPU %, threads, and process ID.
- Memory: This tab displays a list of the process, memory %, threads, and process ID.
- Disk I/O: This tab displays a list of the process, bytes written, bytes read, and process ID.
Network Throughput

The Network Throughput metric displays the observed network throughput in the set time range for the selected user and device. You can view the sent bytes and received bytes by hovering over a data point.
Disk I/O Rate

The Disk I/O Rate metric displays the observed disk input/output rate in the set time range for the selected user and device. You can hover over a data point to view information about the bytes written, bytes read, and processes. You can also click the View all processes button to view additional information, to learn more, please see the Process Info section.
Battery

This metric provides information about the battery level for the selected user’s device at a specific point in time.
Wifi Signal Strength

This metric provides information about the wifi signal strength for the selected user’s device at a specific point in time.
Network Events – Device Events

This metric displays data on any device or network specific events that may have occurred during the set time range such as logons, logoffs, or network disconnections.
Browser Extension Metrics
You can view Browser Extension metrics for a selected user by doing the following:
- Go to Homepage > Digital Experience Management > User Overview
- Open a User Details page for a user by selecting a user from the Users Table of the User Overview page. To learn more please see, User Overview.

3. Click the zoom icon [add inline icon image] to open the User Details page for the selected user. To learn more about, please see User Details.
4. Within the “User Details” navigate to the “Device” drop down menu. From the drop down menu select the browser extension device from the list of devices associated with the user. The page will refresh and list browser extension specific metrics.


