Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Digital Experience Management
    User Overview
    User Overview – Metrics

    User Overview - Metrics

    Metric Details

    About the Metric Details Section

    The metric details section provides you with metric details for monitored SaaS and private applications. Metrics can be viewed by clicking on the SaaS application and private application tabs based on your troubleshooting needs.

    SaaS/Custom Application Tab

    These metrics provide you with data on monitored SaaS applications. The following metrics can be viewed by clicking the SaaS/Custom Application tab:

    • Connectivity to Netskope NewEdge
      • Tunnel Latency – Overlay
      • Network Path Latency – Underlay
    • End-to-End Metrics
      • Time to First Byte, Time to Last Byte
      • Total Response Time
    • Device Performance and Health Metrics
      • CPU Usage
      • Memory Usage
      • Disk Usage
      • Network Throughput
      • Disk I/O Rate
      • Battery
      • Wifi Strength
      • Network Events, Device Events
    • Netskope Metrics
      • Processing Time
    • Application Metrics
      • Round Trip Time
      • TCP Connection Time, SSL Handshake Time
      • Server Response Time
    To view End-to-End Metrics and Application Metrics you must first select an application card from the Monitored Applications section. To learn more, please see Application Cards.

    Private Application Tab

    The Private Application tab provides the following metrics:

    • Network Path View
    • Path Segment Metrics
    • Publisher Utilization Metrics
      • Publisher CPU Usage
      • Publisher Memory Usage
      • Publisher Storage Usage
    • Device Performance and Health Metrics
      • CPU Usage
      • Memory Usage
      • Disk Usage
      • Network Throughput
      • Disk I/O Rate
      • Battery
      • Wifi Strength
      • Network Events, Device Events
    If you have selected an app, you must deselect the app to enable the Private Application tab.

    SaaS Application Metrics

    The SaaS application metrics provide you with data on SaaS applications. You can select an application from the application cards in the Monitored Applications section to view metrics for a specific application. To learn more, please see Application Cards.

    You must select an application card for the End-to-End and Application Metrics to be displayed. To learn more, please see the Application Cards section.

    Connectivity to Netskope NewEdge

    Tunnel Latency – Overlay

    This metric displays the latency within the tunnel between the user’s device and the POP over a selected time range. Latency is measured by sending probes every 30 seconds. The final latency values shown in the chart are based on aggregated probe results. The aggregation depends on the polling frequency configured in the system settings. If the polling frequency is set to 5 minutes, all probe results collected within each 5-minute window are aggregated to compute the latency for that window.

    It’s expected that Overlay and Underlay metrics may differ — sometimes the gap can be quite significant. This is because Overlay is measured using regular TCP packets, which are handled with normal forwarding priority by firewalls, routers, or hubs. In comparison, traceroute (on Windows) uses ICMP packets, which may be deprioritized or rate-limited along the network path.

    In addition, the Overlay represents the mean of multiple measurements collected over a time duration specified in the DEM configuration, whereas the Underlay data reflects a single measurement taken at a specific point in time.

    Therefore, occasional large discrepancies between these two metrics are not a concern. However, if a consistently large gap is observed, further investigation is warranted to understand the underlying cause.

    Network Path Latency – Underlay (E2E)

    This metric tracks the round-trip time (RTT) between a user’s client and a Netskope POP over the page’s selected time range  measured via Traceroute.

    The line chart provides several key behaviors and workflows:

    • Trend Analysis: The interface displays RTT between the user’s device and netskope POP measured via Traceroute as a time series so you can easily observe performance trends over time rather than isolated measurements.
    • POP Identity: Hover over any data point to view the connected POP, timestamp, RTT, and public IP address.
    • Synchronized Zooming: The interface synchronizes chart behavior so that zooming into a time range in this chart simultaneously zooms the hop-by-hop view below.
    • Path Analysis Transition: The tooltip includes a navigational shortcut where you can click View Hop-by-Hop to proceed to path-level analysis for the selected time window.

    Network Path Latency – Underlay (Hop by Hop)

    The network path visualization widget shows all network paths that were taken during the selected time period.The view aggregates all paths taken by the traceroute probes over the time period selected on the page filter into a unified hop by hop view. This view allows administrators  to look at the ISP path taken to reach Netskope and its performance. The thickness of the path is determined by how many probes hit that path measured via traversal share. Traversal shares determine the likely hood of the path carrying users traffic.

    Each node in the path corresponds to a router (or any network component delivering the routing service).

    Each color identifies an AS (Autonomous System). In other words, this color identifies the ISP being traversed.

    For each node, we identify its:

    • location based on its RIR (Regional Internet Registry) registration
    • AS name
    • ISP name

    For each node, we also provide the number of Network Probe tests that passed through it as well as its delay and packet loss.

    Some consecutive nodes on a single path could be unknown. Instead of showing a line with multiple unknown nodes, they are grouped all together (hexagon icon).

    The thickness of a link shows its usage. A thick line means that this path has been taken in a significant amount of Network Probe tests. On the other hand, a thin line means that the link has not been used much.

    The graph is divided into three labeled sections:

    • Internal Network: Hops discovered within the organization’s corporate network.
    • Internet / ISP: Hops discovered across public internet infrastructure that are attributed to a specific ISP and ASN.
    • Netskope Cloud: Netskope’s PoP..

    Administrators can use the following interactive features to analyze path data:

    • Time Slider with Location Awareness: Use the slider sitting above the hop-by-hop graph to filter the graph to a specific time segment. The slider tracks location context, meaning corporate site connections are colored and labeled with the site name, while remote connections are shown in blue and labeled Remote. Hovering over any segment displays the site name, the covered time window, and the number of probe samples collected. You can filter the view either by clicking a segment directly or by using the Site / Remote toggle switch.
    • Edge (Link) Data: Hover over any edge (the line between two nodes) to see the link latency, traversal share, packet loss, and the Average, Median, and P95 latency for that hop. Edge thickness is proportional to traversal share, which makes dominant routes immediately visible.
      • Traversal share is calculated as the percentage of probes that went through a link as compared to the total probes that were sent.
    • Node Data: Hover over any node (router/hop) to view its IP address, traversal share percentage, and RTT to this node from the client measured via Traceroute probes. For internet-segment nodes, the tooltip also shows ISP, ASN, and geographic information. Nodes that did not respond to probes display a distinct visual indicator, and their tooltip shows the total count of unresponsive nodes at that position alongside their combined traversal share.
      • Traversal share is calculated as the percentage of probes that went through a node as compared to the total probes that were sent.
    • Latency Metric Selector: Use the metric toggle switch in the top right to change which latency value displays on the edge labels. You can choose between Average (arithmetic mean), Median (the midpoint value), and P95 (the 95th percentile representing near-worst-case conditions).
    • ISP / ASN Legend: Review the dedicated legend panel to quickly identify the ISPs and Autonomous Systems present in the internet segment of the path, making it easy to attribute latency to specific network operators.
    • Full-Screen Mode: Click the Full Screen button in the top right to expand the hop-by-hop view, which is especially useful for detailed analysis of paths with many hops or multiple parallel routes.
    To learn more about traceroute methodology, please refer to: /en/traceroute-analysis

    Total Connectivity Time

    The Total Connectivity Time metric provides detailed information about the whole process of connecting the NSClient to the Netskope POP. You can hover over a data point on the chart to view information about the DNS resolution time, TCP Connection time, and TLS Handshake time. 

    This metric is only available for DEM Enterprise customers and app probes must be configured. To learn more, please see Digital Experience Management Enterprise and App Probes.

    End-to-End Metrics

    Time to First Byte, Time to Last Byte

    The Time to First Byte (TTFB) corresponds to the time between the NSClient sending the HTTPS request (aka first byte of the request is sent) and when it receives the first byte of data payload (also called the response). The Time to Last Byte (TTLB) corresponds to the time between the NSClient sending the HTTPS request and when it receives the last byte of data payload.

    This metric is only available for DEM Enterprise customers. To learn more about DEM Enterprise, please see Digital Experience Management Enterprise.

    Total Response Time

    The Total Response Time corresponds to the total duration of the App Probe test. It simulates the exact time for a transaction to complete.

    This metric is only available for DEM Enterprise customers. To learn more about DEM Enterprise, please see Digital Experience Management Enterprise.

    Netskope Metrics

    Processing Time

    The Netskope Processing Time metric provides a measurement of the average time it takes for Netskope to process your traffic at any POP used by your organization. The data shows the average latency observed per minute, based on the traffic (including both requests and responses) processed at the last connected POP. The traffic for this measurement is selected through a process of random sampling each minute.

    Transit Time

    The Transit Time corresponds to the total time spent within the Netskope infrastructure. It includes the time spent in the NSProxy to forward the request from the NSClient to the application server, added to the time spent in the NSProxy to forward the response from the application server back to the NSClient.

    This metric is only available for DEM Enterprise customers. To learn more about DEM Enterprise, please see Digital Experience Management Enterprise.

    Application Metrics

    The Application Metrics are displayed after you have selected an application under the Monitored Applications section.

    Round Trip Time

    The observed Round Trip Time (RTT) for the user connecting through the connected Netskope POP to the monitored application.

    TCP Connection Time, SSL Handshake Time

    These metrics correspond to the time needed for the NSProxy to securely connect to the application server. This includes the TCP as well as SSL/TLS handshake processes. The Redirect count provides the number of redirections that have been observed during the select timeframe. The “Connection” time from the Netskope POPs to Applications section corresponds to the time spent by the NSProxy to establish a TCP connection with the targeted server. The “TLS” time from the Netskope POPs to Applications section corresponds to the time spent by the NSProxy to perform the TLS handshake process with the targeted server.

    In case of redirections, this value corresponds to the sum of all occurrences during these redirections.

    This metric is only available for DEM Enterprise customers. To learn more about DEM Enterprise, please see Digital Experience Management Enterprise.

    Server Response Time

    The Server Response Time metric displays the time between the first byte of NSProxy request to the application server and the first byte of response received by the NSProxy. This Server time is the main server performance indicator, as it mainly takes the server processing time into account.

    In case of redirections, this value corresponds to the sum of all occurrences during these redirections.

    This metric is only available for DEM Enterprise customers. To learn more about DEM Enterprise, please see Digital Experience Management Enterprise.

    Private Application Metrics

    The Private Application metrics provide you with data on performance of monitored private application hosts when used by a user. 

    Network Path

    The Network Path view provides a view into all the paths taken by a user’s traffic to the monitored private application hosts and ports along with the performance of each path segment. Since DEM uses Real User Monitoring to measure performance of private applications, only monitored private applications used by the user in the selected time window are shown in this view. If a user has not used an application, the metrics will not show up on the page.

    This view can help admins quickly identify the traffic routing issues, publisher provisioning gaps or identify the path segments that might be negatively impacting the user experience.

    Network Path Node Categories

    The following node categories are displayed in the Network Path metric:

    • Device: The device of the selected user.
    • Gateway: Netskope gateway that the user’s device was connected to. Netskope Client builds a TLS tunnel with the closest Client Gateway located in one of the several Netskope Data Centers. This is where policy is enforced.
    • Stitcher: Publisher builds a TLS tunnel with the closest Publisher Gateway (Stitcher) located in one of the Netskope Data Centers. This is a gateway for the Publisher to connect to the Netskope Cloud. 
    • Publisher: Publisher nodes that were used to connect to private application hosts. 
    • App Host: Monitored private application hosts used by the user in the selected time window.

    Vertices

    Vertices connecting the nodes are represented as the path segments. You can hover over vertices for the following information:

    1. Sessions: This is the total count of sessions that went on this path segment in the selected timeframe.
    2. Latency: This is the observed average latency across all the sessions on the path segment.Hovering over the vertices will show you both Average and Median latency observed across all the user sessions that went to the path segment.

    Policy Block View
    Network Path View now highlights Explicit Policy Blocks when a user is unable to access a private application host due to a policy with the action set to Block. This helps admins instantly identify policy as the cause of access failure and degraded user experience.Once the user is unblocked, normal network path data for the application will appear. The Policy Block node will remain in the view to provide historical context.

    When no private application is selected from the application card above, this view shows all the paths taken by users traffic in the given time window to the monitored private application hosts.

    Selecting a Unique Path to View Path Segment Metrics

    Network Path Filters

    You can use the Network Path metric filters to narrow down the number of unique paths shown in the widget. To learn more about Network Path filters, please see the Network Path Node Categories section.

    About Filters


    You can use the filters menu to view a network path by selecting from the following filter options:

    • Gateways: Filters the path to only show selected gateways.
    • Stitchers:  Filters the path to only show selected stitchers. 
    • Publishers:  Filters the path to only show selected gateways. Only the top 50 worst publishers are selected by default for performance reasons. You can deselect existing selections and select different publishers.
    • Average Latency: Dynamically generates latency ranges based on AVG latency values across path segments and filters path segments to meet the selected latency thresholds.
    • Policy Block: Filters the gateways where the policy block was observed.
    You can select a unique network path to view detailed information on latencies, packet loss rate, and traffic for path segments in a time-series view.

    To View a Unique Path

    You can view a unique network path by selecting from the following options:

    • Click on the nodes to select the path you would like to troubleshoot further.
    • Alternatively, you can use the Network Path filter menu.
    Metrics of the selected path will be displayed after you select a unique network path.
    For the Latency Filter, filter values are dynamic and created based on the medial latency ranges observed in the network path view.

    Path Segment Metrics

    This section shows the performance metrics of individual path segments after a unique path has been selected from the Network Path view. This section will allow admins to correlate user experience issues to the selected segments. You can view the following Network Path Segments:

    • Client to Gateway
    • Gateway to Stitcher
    • Stitcher to Publisher

    Client to Gateway 

    Latency
    Latency measures the delay in user’s application traffic between the client and the Gateway tunnel measured from the client. It is displayed as a time series, updated every minute to show how latency changes over time.

    Latency is calculated as a running moving weighted average, which gives more importance to recent traffic measurements while smoothing out short-term fluctuations. This helps identify long-term network trends and potential performance issues.

    Loss Rate
    Packet loss is the percentage of data packets lost between the client and the Gateway. It is shown as a time series with 1-minute granularity.A high loss rate may indicate network congestion or issues, affecting reliability and performance.

    Traffic
    Traffic refers to the total amount of data (in bytes) uploaded and downloaded between the Client and the Gateway across all user connections in the past one minute. 

    Gateway to Stitcher

    Latency

    Latency refers to the measured delay in a user’s traffic between the Gateway and the Stitcher tunnel measured from the Gateway, plotted as a time series with 1-minute granularity. This is a measure of congestion in the Gateway to Stitcher tunnel which carried the user’s traffic.

    Latency is calculated as a running moving weighted average, which gives more importance to recent measurement while smoothing out short-term fluctuations. This helps identify long-term network trends and potential performance issues.

    Loss Rate

    Loss rate is the rate of packet loss observed within the Gateway to Stitcher tunnel over the past minute.
    It represents the percentage of NPA real user data packets that fail to reach the Stitcher.

    Stitcher to Publisher

    Latency

    Latency refers to the measured delay in a user’s traffic between the Stitcher and the Publisher tunnel measured from the Stitcher, plotted as a time series with 1-minute granularity. This is a measure of congestion in the Stitcher to Publisher tunnel which carried the user’s traffic.

    Latency is calculated as a running moving weighted average, which gives more importance to recent measurement while smoothing out short-term fluctuations. This helps identify long-term network trends and potential performance issues.

    Loss Rate
    The rate of packet loss observed within the Stitcher to Publisher tunnel over the past minute..


    Sessions

    You can view the session details to map the performance on the path segments (Client to Gateway, Gateway to Stitcher, or Stitcher to Publisher). To view the sessions for a user, please do the following:

    1.  Hover a data point in a path segment metric.
    2. Click on the Sessions button.
    3. The Sessions window will open.
    The Sessions window shows the Active User sessions and its details in the selected window on the given path segment. Session details are available for all 3 paths segments.

    Sessions Windows

    The Sessions Window provides detailed visibility into active user sessions for a selected user, time frame, and path segment. It also includes session close reasons to identify tunnel tear down by publisher disconnection.

    The Sessions Window shows the following information:

    • Time Range: The selected time window from the time series chart on the previous screen.
    • User: The ID of the user being analyzed.
    • Private App Host: The host of the private application accessed during the session.
    • Private App: The name of the private application as defined by policy.
    • Private App Port: The port(s) through which traffic was observed.
    • Sessions: This table lists all sessions associated with the application host shown at the top of the screen.
      • Start Time: When the session began. 
      • End Time: When the session ended.
      • Port: The destination port used during the session.
      • Total Traffic (RX/TX): Total download (RX) and upload (TX) traffic during the session.
      • Session Close Reason: Reason the session ended. Possible values include:
        • Dropped due to publisher disconnection
        • Dropped based on policy
        • Routine cleanup

    Other Impacted Users 

    The “Other Impacted Users” metric helps you identify users who shared the same tunnel as the selected user during a period of latency degradation. You can view this metric by hovering over a data point in a Gateway to Sticher or Stitcher to Publisher metric, and clicking the “Other Impacted Users” button. This allows you to assess the potential scope of impact and optionally reach out to those users for confirmation or further investigation.

    How to Filter

    You can filter this view by selecting the available latency thresholds in the dropdown menu. The system will:

    1. Analyze the selected user’s tunnel paths within the path segments
    2. Identify tunnels where observed latency meets or exceeds the chosen threshold.
    3. Shows list of other users who had active connections for any DEM monitored private application hosts on those same tunnels during the selected time window.

    Available Latency Thresholds

    1. ≥ 50 ms: Shows users who shared tunnels with latency of 50 ms or more.
    2. ≥ 100 ms: Shows users who shared tunnels with latency of 100 ms or more.
    3. ≥ 200 ms: Shows users who shared tunnels with latency of 200 ms or more.

    Publisher Utilization Metrics

    It shows CPU, memory, and storage usage over time for publishers the user used to access private apps. Monitor these to spot overloads, prevent performance issues, and ensure smooth app access.

    Publisher CPU Usage

    The percentage of processing capacity used by the publisher in the set time range for the selected user and device.

    Publisher Memory Usage

    The percentage of system memory in use in the set time range for the selected user and device.

    Publisher Storage Usage

    The percentage of allocated storage space consumed in the set time range for the selected user and device.

    Device Performance and Health Metrics

    CPU Usage

    The CPU Usage metric displays the observed CPU Usage in the set time range for the selected user and device. You can hover over the time data points to view more detailed information about the CPU, processes, and threads. You can also click the View all processes button to view additional information, to learn more, please see the Process Info section.

    CPU usage displayed in DEM may differ from the values shown in Windows Task Manager. This is expected behavior on Windows devices and does not indicate inaccurate data. The Netskope client measures CPU usage using the % Processor Time counter, while Windows Task Manager uses the % Processor Utility counter, which accounts for dynamic CPU frequency boosting such as Intel Turbo Boost or AMD Precision Boost. As a result, Task Manager may report higher CPU usage values than what is displayed on the DEM dashboard for the same workload.

    Memory Usage

    The Memory Usage metric displays the observed memory usage in the set time range for the selected user and device. You can hover over the time data points to view more detailed information about the memory, processes, and threads. You can also click the View all processes button to view additional information, to learn more, please see the Process Info section.

    Disk Usage

    The Disk Usage metric displays information about the disk usage of the selected user and device for the set time range. To view the disk usage percentage at a selected time, hover over the associated data point. 

    Process Info

    The Process Info window provides you with additional details about the process info. To open the Process Info window for a specific timestamp, do the following:

    1.  Select a set timestamp by hovering over the corresponding data point on the CPU Usage, Memory Usage, or Disk Usage metric.
    2. A box of data will appear when you hover over a timestamp.
    3. Click the View all processes button.
    4. The Process Info window will open.
    5. View information for the selected timestamp by clicking on the following tabs:
      1. CPU: This tab displays a list of the process, CPU %, threads, and process ID.
      2. Memory: This tab displays a list of the process, memory %, threads, and process ID.
      3. Disk I/O: This tab displays a list of the process, bytes written, bytes read, and process ID.

    Network Throughput

    The Network Throughput metric displays the observed network throughput in the set time range for the selected user and device. You can view the sent bytes and received bytes by hovering over a data point.

    Disk I/O Rate

    The Disk I/O Rate metric displays the observed disk input/output rate in the set time range for the selected user and device. You can hover over a data point to view information about the bytes written, bytes read, and processes. You can also click the View all processes button to view additional information, to learn more, please see the Process Info section.

    Battery

    This metric provides information about the battery level for the selected user’s device at a specific point in time.

    Wifi Signal Strength

    This metric provides information about the wifi signal strength for the selected user’s device at a specific point in time.

    Network Events – Device Events

    This metric displays data on any device or network specific events that may have occurred during the set time range such as logons, logoffs, or network disconnections.

    Browser Extension Metrics

    You can view Browser Extension metrics for a selected user by doing the following:

    1. Go to Homepage > Digital Experience Management > User Overview
    2. Open a User Details page for a user by selecting a user from the Users Table of the User Overview page. To learn more please see, User Overview.

    3. Click the zoom icon [add inline icon image] to open the User Details page for the selected user. To learn more about, please see User Details.

    4. Within the “User Details” navigate to the “Device” drop down menu. From the drop down menu select the browser extension device from the list of devices associated with the user. The page will refresh and list browser extension specific metrics.

    In this Topic
    • User Overview - Metrics