Netskope LogoNetskope Logo
  • セキュリティサービス
  • AIサービス
  • ネットワークサービス
  • 分析サービス
  • 統合
  • getting-started.svg始める
    • サポート
    • コミュニティ
    • Netskope.com
    © 2026 無断転載を禁じます。Netskope 株式会社
    トップページ
    DLP - 情報漏洩対策
    データリネージ

    データリネージ

    この機能は、RUH1でホストされているテナントでは利用できません。

    Data Lineage is a new product designed to give you unparalleled visibility into your organization’s data. It provides a comprehensive, visual map of the data’s entire lifecycle, from its origin, through various stages of modification and transformation, all the way to its usage and potential exfiltration.

    データの流れの全体像を提供することで、Data Lineage は次のことに役立ちます。

    • Enhance incident context: Quickly understand the full story behind an incident.
    • Facilitate forensic investigations: Conduct more efficient and thorough investigations.
    • Identify risky movements: Proactively spot and address potential data exfiltration risks before they happen.

    主な特徴

    データリネージは、既存のNetskope製品から既存のイベントを自動的に再編成することで機能するため、事前の設定は不要です。クラウドおよびエンドポイント環境全体で個々のファイル アクティビティ イベントをキャプチャし、ファイル識別子、ファイル メタデータ、ユーザー コンテキスト、およびタイムスタンプを使用してそれらを関連付けます。 これらの関連する観測結果は有向グラフとして視覚化され、調査担当者はファイル名の変更、編集、複数回の転送を経ても、ファイルの発信元から宛先までを追跡することができる。

    It’s centrally managed and available in the Netskope UI. You can navigate to Data Lineage by using the link in the DLP Incident page.

    • Comprehensive File Activity Tracking: Records a wide range of user-initiated file operations, including copying, creating, downloading, editing, moving, renaming, sharing, and uploading.
    • Integrated Incident Investigation: Seamlessly link from a DLP incident page directly to the file’s lineage for deeper context.
    • Interactive Lineage Graph: A dedicated tab provides a graphical representation of the file’s lineage with rich, interactive features:
      • Zoom and Focus: Easily zoom in and out to control the level of detail and shift the focus point.
      • Tooltip: グラフ内の任意の要素にマウスカーソルを合わせると、ファイルまたはユーザーのアクティビティに関する詳細情報が表示されます。
      • Expandable View: Hide specific components to reduce clutter or expand them for more detail.
      • Graph Manipulation: Drag and rearrange the graph to fit the user’s needs.
      • Dynamic File Switching: Effortlessly switch the focus to view the lineage of different files.

    データリネージの仕組み

    活動の捕捉

    Data lineage works by continuously monitoring file activity across your entire ecosystem—from endpoints (laptops, mobile devices) to cloud applications. Every time a file is created, moved, copied, uploaded, or downloaded, we capture a detailed record of that event, including:

    • 誰がファイルにアクセスしたか
    • それが起こったとき
    • ファイルの出所と行き先
    • The file’s unique characteristics (name, content signature, cloud app ID)

    Think of each captured event as a snapshot in time—a single step in the file’s journey.

    点と点をつなぐ

    A file rarely stays in one place. It might be created on a laptop, uploaded to Google Drive, shared to a colleague, downloaded to their device, then uploaded to Slack. Each of these is a separate snapshot, but they represent the same file moving through your environment.

    Our platform automatically connects these individual snapshots into a complete journey by:

    1. Matching unique identifiers: Cloud applications assign unique IDs to files—when we see the same ID across different events, we know it’s the same file
    2. Comparing content signatures: Even if a file is renamed, its cryptographic fingerprint (hash) remains the same, allowing us to track it across name changes
    3. Intelligent correlation: When direct identifiers aren’t available, we analyze multiple signals together—file names, user activity, timestamps, locations, and more—to confidently determine when different events represent the same file’s journey

    全体像を視覚化する

    When you search for a file’s lineage, the system:

    1. Starts from your file of interest (the “starting point”)
    2. Follows all connections backward to find its origins and forward to see where it traveled
    3. Assembles these connections into an interactive visual timeline showing the complete path

    This gives you a complete end-to-end view. You can trace any sensitive file back to its original source or forward to see everywhere it has spread, even if it was renamed, moved between multiple apps, or transferred through several users.

    結果

    Instead of seeing isolated security events, you get the full story: where sensitive data originated, how it moved through your organization, who touched it along the way, and where it exists now. This comprehensive visibility is essential for investigating data breaches, enforcing DLP policies, and maintaining compliance.

    既知の制限事項

    データリネージは、クラウドアプリケーション全体におけるファイルの移動状況を可視化しますが、すべてのアクションやシナリオを網羅するわけではありません。このセクションでは、適切な期待値を設定するのに役立つよう、現在の範囲と既知のギャップについて概説します。

    データソース

    Data Lineage builds its graph from the following data sources:

    • Inline (Client): Real-time traffic captured via the Netskope Client
    • CASB API: Events retrieved through API-based integrations with cloud applications
    • Endpoint DLP: Limited to content event, and limited to file copy to USB
    • Alerts: Generated by any of the above data sources

    監視対象はapp trafficのみです。Web trafficは対象範囲外です。

    What Is Tracked

    Data Lineage monitors file-level objects (documents, attachments, spreadsheets, presentations, folders, media files, etc.). It does not track non-file objects such as chat messages, calendar events, or database records.

    支援対象となる活動は以下のとおりです。

    • Create

    • Copy

    • ダウンロードはこちら

    • 編集

    • Invite

    • Move

    • Rename

    • Share

    • アップロード

    Key Limitations

    • Not all application activities are captured: Each data source (Inline, CASB API) has inherent differences in what information it reports. Some activities may be missing, misclassified, or lack the metadata (e.g., file name, file ID, hash) needed to build an accurate lineage graph. The completeness of lineage depends on which data sources are enabled for a given application.
    • Activity misclassification: Certain activities may be reported differently than how the user performed them. For example, a Move may appear as a Copy or Edit, a Create may appear as an Upload. These discrepancies arise from how individual applications report events to the data sources.
    • Disconnected graph nodes: When file metadata changes between activities — such as a different file hash after upload/download, or a renamed file without a stable identifier — Data Lineage may not be able to connect related events into a continuous graph. This results in orphaned nodes or broken chains in the lineage view.
    • Duplicate file ambiguity: When multiple upload/download activities involve files with the same file name and hash (e.g., the same file sent between users), Data Lineage may not accurately pair each download with its corresponding upload.
    • Incomplete coverage without CASB API: Inline-only deployments will have reduced accuracy for certain activities. CASB API events often provide richer metadata (file IDs, target users, original filenames) that Inline events may lack. Enabling CASB API alongside Inline significantly improves lineage accuracy.
    • Application-specific gaps: Not all applications expose the same level of event detail. Some apps do not report certain activities at all, or report them without sufficient file metadata to construct lineage. Coverage varies by application and by activity type.

    Recommendations

    • Contact your Netskope representative for the latest list of supported applications and activity coverage.

    • Enable both Inline and CASB API data sources where available to maximize lineage accuracy.

    • Treat Data Lineage as a best-effort view of file movement across your environment. It is designed to surface the most common and critical file flows, but gaps will exist.

    このトピックでは
    • データリネージ