Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Netskope Cloud Exchange
    Get Started with Cloud Exchange
    Netskope Tenant Plugin

    Netskope Tenant Plugin

    Release Notes

    1.6.1 (Requires minimum Cloud Exchange version 6.1.0)

    Added

    • Added coordinated cleanup of the shared client status iterator so it is removed only when no Netskope plugin (Risk Exchange or Log Shipper) is using it.
    • Type cast large ID fields to String to avoid UI rounding them off while rendering.

    1.6.0

    Fixed

    • Updated the historical pull logic to ensure that valid events within the requested time range from the last batch are processed.
    • Updated handling for pulling alerts/events from stored checkpoint.

    1.5.3

    Changed

    • Improved exception handling when forensics service is not enabled on Netskope Tenant.
    • Updated tooltip for V1 API token.
    • Added resolutions for common errors.

    1.5.2

    Fixed

    • Updated iterator index with analytics type.

    1.5.1
    Fixed

    • Updated WebTx creds retrieval interval on authentication error.
    • Updated pulling workflow.

    1.5.0
    Fixed

    • Added support to pull forensics for DLP Incident events. To pull and ingest these fields update your CLS Netskope plugin version to 2.3.0, CTO Netskope plugin version to 2.3.0 and CE version to 5.1.2.

    1.4.2
    Fixed

    • Updated pulling workflow.
    • Bug Fix.

    1.4.1
    Fixed

    • Bug Fix.

    1.4.0
    Added

    • Added support for Client status events. To pull and ingest this event type update your CLS Netskope plugin version to 2.2.0.

    1.3.0
    Added

    • Enhanced field learning workflow with updated plugin to identify fields and their data types.

    1.2.0
    Added

    • Added support for device and content alerts.

    1.1.0

    Changed

    • Enhanced pulling workflow.
    • Updated authentication for V1 token.

    1.0.0
    Added

    • Initial release.

    This document explains how to configure the Netskope Tenant v1.6.1 plugin in Cloud Exchange. This plugin is responsible for configuring Netskope tenants and collecting alerts, events, and WebTx data from the Netskope tenant.

    Starting with Cloud Exchange 5.1.0, Netskope tenants are configured through a Tenant plugin and not through Settings > Netskope Tenants.

    Prerequisites

    To complete this configuration, you need:

    • Connectivity to a Netskope tenant with permission to generate API tokens.
    • To pull and ingest Client Status events, you will need to configure the Log Shipper plugin. 
    • To pull and ingest Forensics Data for Incident events, you will need Cloud Exchange v5.1.2 or above and CLS Netskope plugin v2.3.0 or above. 
    Tenant Plugin Support

    This plugin is responsible for configuring Netskope tenants and collecting alerts, events, and WebTx data (via Netskope LogStreaming) from the Netskope tenant. To access the plugin, you need a Netskope Tenant.

    Data TypeSupport
    Event TypesYes (Audit, Application, Infrastructure, Network, Incident, Page, Endpoint, Client status)
    Alert TypesYes (DLP, Malware, Policy, Compromised Credential, Malsite, Quarantine, Remediation, Security Assessment, Watchlist, CTEP, UBA, Device, Content)
    WebTxYes (via Netskope LogStreaming)

    Note

    • CLS WebTX based on Google Pub Sub Lite is deprecated. Refer to Netskope Product EOL/EOS Announcements for more details.
    • For ingesting WebTX logs to your Log delivery destinations like SIEM, SOAR, XDR, Data Lake, use the AWS Netskope Log Streaming or Azure Netskope Log Streaming plugin.
    Permissions
    • The required permissions (privilege levels) per plugin are available in the REST API scopes.
    • Need v2 token(RBACv3 API Token) created using the Netskope Cloud Exchange Role.
    API Details

    Here’s a list of the APIs used.

    Validation
    API EndpointMethodUse Case
    /api/v1/app_instancesGETTo validate a v1 token.
    /api/v2/events/dataexport/events/alertGETTo validate a v2 token while configuring tenant.
    Alerts
    API EndpointMethodUse Case
    /api/v2/events/dataexport/alerts/dlpGETPull DLP Alerts from the Netskope tenant.
    /api/v2/events/dataexport/alerts/malwareGETPull Malware Alerts from the Netskope tenant.
    /api/v2/events/dataexport/alerts/remediationGETPull Remediation Alerts from the Netskope tenant.
    /api/v2/events/dataexport/alerts/securityassessmentGETPull Security Assessment Alerts from the Netskope tenant.
    /api/v2/events/dataexport/alerts/ctepGETPull CTEP Alerts from the Netskope tenant.
    /api/v2/events/dataexport/alerts/malsiteGETPull Malsite Alerts from the Netskope tenant.
    /api/v2/events/dataexport/alerts/policyGETPull Policy Alerts from the Netskope tenant.
    /api/v2/events/dataexport/alerts/quarantineGETPull Quarantine Alerts from the Netskope tenant.
    /api/v2/events/dataexport/alerts/ubaGETPull UBA Alerts from the Netskope tenant.
    /api/v2/events/dataexport/alerts/watchlistGETPull Watchlist Alerts from the Netskope tenant.
    /api/v2/events/dataexport/alerts/deviceGETPull Device Alerts from the Netskope tenant.
    /api/v2/events/dataexport/alerts/contentGETPull Content Alerts from the Netskope tenant.
    Events
    API EndpointMethodUse Case
    /api/v2/events/dataexport/events/pageGETPull Page Events from the Netskope tenant.
    /api/v2/events/dataexport/events/applicationGETPull Application Events from the Netskope tenant.
    /api/v2/events/dataexport/events/auditGETPull Audit Events from the Netskope tenant.
    /api/v2/events/dataexport/events/infrastructureGETPull Infrastructure Events from the Netskope tenant.
    /api/v2/events/dataexport/events/networkGETPull Network Events from the Netskope tenant.
    /api/v2/events/dataexport/events/incidentGETPull Incident Events from the Netskope tenant
    /api/v2/incidents/dlpincidents/{id}/forensicsGETpull Incident Forensics per dlp_incident_id.
    /api/v2/events/dataexport/events/endpointGETPull Endpoint Events from the Netskope tenant.
    api/v2/events/dataexport/iterator/netskope_ce_cs_iterator?eventtype=clientstatusPOSTCreate a Client Status Iterator.
    /api/v2/events/dataexport/iterator/<iterator_name>GETCheck Status of a Client Status Iterator.
    /api/v2/events/dataexport/iterator/<iterator_name>/events?operation=nextGETFetch data from a Client Status Iterator.
    api/v2/events/dataexport/iterator/<iterator_name>DELETEDelete a Client Status Iterator.
    Validate a v1 token

    API Endpoint: https://<tenant-url>/api/v1/app_instances
    Method: GET
    Request Headers

    KeyValue
    User-Agentnetskope-ce-6.1.0

    Request Parameters

    KeyValue
    oplist
    limit1

    Payload

    {"token": <netskope_api_v1_token>}

    Sample API Response

    {
        "status": "success",
        "data": [
            {
                "app": "Oracle Aconex",
                "instance_name": "46",
                "instance_id": "46",
                "type": "Custom",
                "tags": [
                    "Unsanctioned"
                ],
                "last_modified": "2025-02-24 09:59:54",
                "custom": "0",
                "app_id": "46"
            }
        ]
    }
    Validate a v2 Token

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/events/alert
    Method: GET
    Request Headers

    KeyValue
    Netskope-API-Token<netskope_api_v2_token>
    User-Agentnetskope-ce-6.1.0

    Sample API Response

    {
        "_id": "abc350cdb1e1958a03ccd13c",
        "access_method": "Endpoint",
        "acked": "false",
        "action": "block",
        "activity": "Insert",
        "alert": "yes",
        "alert_name": "TestBlock",
        "alert_type": "Device",
        "app": "",
        "category": "",
        "cci": 0,
        "ccl": "unknown",
        "count": 1,
        "device_classification": "not configured",
        "organization_unit": "",
        "os": "macOS",
        "other_categories": [],
        "policy": "TestBlock",
        "timestamp": 1719994603,
        "traffic_type": "",
        "type": "endpoint",
        "ur_normalized": "kmaheshwari@netskope.com",
        "user": "kmaheshwari@netskope.com",
        "userkey": "kmaheshwari@netskope.com",
        "record_type": "alert",
        "to_object": "",
        "account_id": "",
        "CononicalName": "",
        "malsite_country": "",
        "src_geoip_src": 0,
        "object": "",
        "fromlogs": "",
        "ext_labels": [],
        "last_timestamp": 0,
        "justification_type": "",
        "tss_mode": "",
        "user_id": "",
        "password_type": "",
        "suppression_key": "",
        "connection_id": 0,
        "sha256": "",
        "site": "",
        "src_longitude": 0.0,
        "os_version": "",
        "resp_cnt": 0,
        "src_timezone": "",
        "user_confidence_index": 0,
        "browser_version": "",
        "dst_region": "",
        "last_app": "",
        "dlp_rule_count": 0,
        "sessionid": "",
        "profile_id": "",
        "threshold": 0,
        "org": "",
        "suppression_end_time": 0,
        "nsdeviceuid": "",
        "parent_id": "",
        "compliance_standards": [],
        "true_obj_category": "",
        "severity": "",
        "sa_profile_id": 0,
        "malsite_longitude": 0.0,
        "sa_rule_id": "",
        "region_name": "",
        "device": "",
        "dlp_mail_parent_id": "",
        "evt_src_chnl": "",
        "malsite_latitude": 0.0,
        "request_id": 0,
        "sa_rule_severity": "",
        "dst_latitude": 0.0,
        "universal_connector": "",
        "malsite_ip_host": "",
        "referer": "",
        "dst_geoip_src": 0,
        "severity_level": "",
        "conn_starttime": 0,
        "dsthost": "",
        "last_location": "",
        "useragent": "",
        "breach_description": "",
        "shared_domains": "",
        "asset_object_id": "",
        "malicious": "",
        "sa_rule_name": "",
        "breach_target_references": "",
        "justification_reason": "",
        "conn_duration": 0,
        "object_id": "",
        "userPrincipalName": "",
        "alert_id": "",
        "exposure": "",
        "mime_type": "",
        "true_obj_type": "",
        "user_generated": "",
        "total_collaborator_count": 0,
        "browser_session_id": 0,
        "dst_timezone": "",
        "appsuite": "",
        "retro_scan_name": "",
        "page_site": "",
        "last_device": "",
        "dlp_unique_count": 0,
        "sAMAccountName": "",
        "src_zipcode": "",
        "file_size": 0,
        "domain": "",
        "title": "",
        "conn_endtime": 0,
        "dst_location": "",
        "telemetry_app": "",
        "netskope_pop": "",
        "malsite_region": "",
        "serial": "",
        "web_universal_connector": "",
        "modified": 0,
        "iaas_remediated": "",
        "internal_collaborator_count": 0,
        "object_type": "",
        "domain_ip": "",
        "orig_ty": "",
        "threshold_time": 0,
        "src_location": "",
        "dlp_profile": "",
        "data_type": "",
        "web_url": "",
        "src_time": "",
        "severity_level_id": 0,
        "resource_category": "",
        "browser": "",
        "region_id": "",
        "dlp_incident_id": 0,
        "last_country": "",
        "threat_match_value": "",
        "netskope_activity": "",
        "server_bytes": 0,
        "dlp_file": "",
        "two_factor_auth": "",
        "breach_date": 0,
        "url": "",
        "policy_actions": [],
        "req_cnt": 0,
        "external_collaborator_count": 0,
        "dst_country": "",
        "log_file_name": "",
        "scan_type": "",
        "src_region": "",
        "threat_source_id": 0,
        "notify_template": "",
        "malsite_category": [],
        "numbytes": 0,
        "dlp_is_unique_count": "",
        "account_name": "",
        "file_path": "",
        "file_lang": "",
        "suppression_start_time": 0,
        "custom_attr": {},
        "email_source": "",
        "sanctioned_instance": "",
        "owner": "",
        "bypass_traffic": "",
        "src_latitude": 0.0,
        "page": "",
        "dstip": "",
        "hostname": "",
        "dstport": 0,
        "matched_username": "",
        "src_country": "",
        "file_cls_encrypted": false,
        "md5": "",
        "iaas_asset_tags": [],
        "file_type": "",
        "malsite_id": "",
        "app_session_id": 0,
        "protocol": "",
        "userip": "",
        "breach_media_references": "",
        "instance": "",
        "app_activity": "",
        "client_bytes": 0,
        "sa_profile_name": "",
        "instance_id": "",
        "http_transaction_count": 0,
        "breach_id": "",
        "transaction_id": 0,
        "from_user": "",
        "last_region": "",
        "managementID": "",
        "shared_with": "",
        "resource_group": "",
        "appcategory": "",
        "event_type": "",
        "asset_id": "",
        "srcip": "",
        "managed_app": "",
        "dlp_parent_id": 0,
        "breach_score": "",
        "dst_zipcode": "",
        "dlp_rule_severity": "",
        "orignal_file_path": "",
        "threat_match_field": "",
        "dst_longitude": 0.0,
        "external_email": 0,
        "policy_id": "",
        "dlp_rule": ""
    }
    Get Compromised Credential Alerts

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/alerts/compromisedcredential
    Method: GET
    Request Headers

    KeyValue
    Netskope-API-Token<netskope_api_v2_token>
    User-Agentnetskope-ce-6.1.0

    Sample API Response

    {
        "_id": "20575270a59c8ef1d85d535c",
        "acked": "false",
        "alert": "yes",
        "alert_name": "Secret share",
        "alert_type": "Compromised Credential",
        "app": "Friend2Friend",
        "category": "Cloud Storage",
        "cci": 29,
        "ccl": "poor",
        "count": 1,
        "organization_unit": "netskope.local/Netskope/Active Users/US & International/Full Time",
        "timestamp": 1727659690,
        "type": "nspolicy",
        "ur_normalized": "dte1953ce410-0495t@test.netskope.com",
        "user": "dte1953ce410-0495t@test.netskope.com",
        "userkey": "dte1953ce410-0495t@test.netskope.com",
        "division": "",
        "external_email": 0,
        "mail": "",
        "sAMAccountName": "",
        "password_type": "",
        "userPrincipalName": "",
        "breach_date": 0,
        "sAMAccountType": "",
        "breach_id": "",
        "breach_score": "",
        "department": "",
        "employeeType": "",
        "matched_username": "",
        "breach_media_references": "",
        "email_source": "",
        "breach_description": "",
        "breach_target_references": "",
        "distinguishedName": ""
    }
    Get DLP Alerts

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/alerts/dlp
    Method: GET
    Request Headers

    KeyValue
    Netskope-API-Token<netskope_api_v2_token>
    User-Agentnetskope-ce-6.1.0

    Sample API Response

    {
        "_id": "31365da11ecc94a0d7edfb6f",
        "access_method": "API Connector",
        "acked": "false",
        "action": "alert",
        "alert": "yes",
        "alert_name": "GDrive Customer metadata shared externally",
        "alert_type": "DLP",
        "app": "Google Drive",
        "appcategory": "Cloud Storage",
        "browser": "unknown",
        "category": "Cloud Storage",
        "ccl": "high",
        "device": "Other",
        "dst_country": "US",
        "dst_geoip_src": 1,
        "dst_latitude": 37.40599060058594,
        "dst_location": "Mountain View",
        "dst_longitude": -122.0785140991211,
        "dst_region": "California",
        "dstip": "172.217.14.78",
        "exposure": "organisation_wide_link",
        "ext_labels": [
            {
                "data_classification_label": "pym/uducbb2126/encryption_level_11",
                "id": "6e05576c-782b-42b4-b8f7-71dfb9ffb5a0",
                "instance": "uducbb2126",
                "name": "encryption_level_11",
                "vendor": "pym"
            },
            {
                "data_classification_label": "ydu/ldmwyo2852/encryption_level_11",
                "id": "20c2b17d-7612-4349-b1e1-62d0d6b48ccb",
                "instance": "ldmwyo2852",
                "name": "encryption_level_11",
                "vendor": "ydu"
            },
            {
                "data_classification_label": "uwa/eqpoco8593/encryption_level_9",
                "id": "6f77b892-3888-4148-8168-d954856d2fea",
                "instance": "eqpoco8593",
                "name": "encryption_level_9",
                "vendor": "uwa"
            }
        ],
        "file_lang": "ENGLISH",
        "file_path": "/My Drive/Clickhouse/Tenant Migration across MPs",
        "file_size": 196869,
        "file_type": "application/vnd.google-apps.document",
        "instance": "netskope.com",
        "instance_id": "netskope.com",
        "local_sha256": "edd7df8bb5a774a7531a389287a3bd71cf8e62197d93a205860003ed8339a4de",
        "md5": "4bf7680195ecaed55e3edabb5d95ca01",
        "mime_type": "application/vnd.google-apps.document",
        "modified": 1613760236,
        "object": "Tenant Migration across MPs",
        "object_id": "14WLYNjJxKgEyqIoNAcb57aPGx9_klcxTo3MyjF82rGg",
        "object_type": "File",
        "organization_unit": "netskope.local/Netskope/Active Users/US & International/Full Time",
        "os": "unknown",
        "owner": "foobar",
        "policy": "GDrive Customer metadata shared externally",
        "request_id": "2459149802892628500",
        "scan_type": "Ongoing",
        "site": "Google Drive",
        "suppression_key": "Tenant Migration across MPs",
        "timestamp": 1716551379,
        "title": "Tenant Migration across MPs",
        "traffic_type": "CloudApp",
        "type": "nspolicy",
        "ur_normalized": "rowkuxqaxdxnlnlw",
        "url": "https://drive.google.com/open?id=14WLYNjJxKgEyqIoNAcb57aPGx9_klcxTo3MyjF82rGg",
        "user": "RoWkuxQAxDxNlNLw",
        "userkey": "RoWkuxQAxDxNlNLw",
        "record_type": "alert",
        "page_site": "",
        "act_user": "",
        "src_longitude": 0.0,
        "dst_timezone": "",
        "device_classification": "",
        "to_user": "",
        "dlp_file": "",
        "connection_id": 0,
        "external_collaborator_count": 0,
        "incident_id": 0,
        "dlp_fingerprint_classification": "",
        "activity": "",
        "from_storage": "",
        "user_confidence_index": 0,
        "browser_version": "",
        "dynamic_classification": "",
        "smtp_to": [],
        "dlp_rule_severity": "",
        "shared_with": "",
        "outer_doc_type": 0,
        "orignal_file_path": "",
        "channel": "",
        "data_type": "",
        "userip": "",
        "sanctioned_instance": "",
        "src_region": "",
        "true_filetype": "",
        "dlp_rule_count": 0,
        "shared_domains": "",
        "owner_pdl": "",
        "dlp_unique_count": 0,
        "transaction_id": 0,
        "browser_session_id": 0,
        "userCountry": "",
        "bcc": "",
        "displayName": "",
        "srcip": "",
        "dlp_mail_parent_id": "",
        "hostname": "",
        "classification_name": "",
        "protocol": "",
        "sAMAccountName": "",
        "violating_user": "",
        "manager": "",
        "src_time": "",
        "src_country": "",
        "true_obj_category": "",
        "message_size": 0,
        "dlp_fingerprint_score": 0,
        "src_geoip_src": 0,
        "os_version": "",
        "true_type_id": 0,
        "to_storage": "",
        "tss_mode": "",
        "managed_app": "",
        "file_password_protected": "",
        "dlp_incident_id": 0,
        "managementID": "",
        "dlp_fingerprint_match": "",
        "src_timezone": "",
        "mail": "",
        "total_collaborator_count": 0,
        "from_user": "",
        "app_activity": "",
        "user_id": "",
        "custom_attr": {},
        "group": "",
        "file_cls_encrypted": false,
        "universal_connector": "",
        "message_id": "",
        "file_category": "",
        "dlp_parent_id": 0,
        "sub_type": "",
        "src_latitude": 0.0,
        "userPrincipalName": "",
        "dlp_is_unique_count": "",
        "dlp_rule_score": 0,
        "src_zipcode": "",
        "dlp_rule": "",
        "referer": "",
        "app_session_id": 0,
        "parent_id": "",
        "retro_scan_name": "",
        "src_location": "",
        "dst_zipcode": "",
        "dlp_profile": "",
        "true_obj_type": "",
        "violating_user_type": "",
        "policy_id": "",
        "web_universal_connector": "",
        "appsuite": "",
        "severity": "",
        "sha256": "",
        "collaborated": "",
        "page": ""
    }
    Get Malware Alerts

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/alerts/malware
    Method: GET
    Request Headers

    KeyValue
    Netskope-API-Token<netskope_api_v2_token>
    User-Agentnetskope-ce-6.1.0

    Sample API Response

    {
        "TSS-scan": "TSS-Scan-V3",
        "_id": "389551cd1bdaa1ae4947c334",
        "access_method": "Client",
        "acked": "false",
        "action": "Detection",
        "activity": "Browse",
        "alert": "yes",
        "alert_name": "GT:JS.Adware.Popunder.4.34B7F109",
        "alert_type": "Malware",
        "app": "hitomi",
        "app_name": "hitomi",
        "app_session_id": 4113602168491103340,
        "appcategory": "Adult Content - Pornography",
        "browser_session_id": 2610528494199657827,
        "category": "Adult Content - Pornography",
        "cci": "",
        "ccl": "",
        "connection_id": 5767115909713174088,
        "count": 1,
        "detection_engine": "Netskope AV",
        "device": "Linux Device",
        "device_classification": "not configured",
        "dst_country": "UA",
        "dst_latitude": 50.45465850830078,
        "dst_location": "Kyiv",
        "dst_longitude": 30.523799896240234,
        "dst_region": "Kyiv",
        "dst_timezone": "Europe/Kyiv",
        "dst_zipcode": "N/A",
        "dstip": "185.255.122.62",
        "file_category": "Text",
        "file_id": "1dda26cbf77944ccb931f3444b554c74",
        "file_size": 2277,
        "file_type": "text/html",
        "hostname": "ub20-50-5-28",
        "incident_id": 7718454634228557343,
        "instance": "",
        "local_md5": "cda70ab0130f915723a53a5d9270e7a5",
        "malware_id": "3d81bec28fff68180bf8baa5727924ba",
        "malware_name": "GT:JS.Adware.Popunder.4.34B7F109",
        "malware_profile": "1",
        "malware_severity": "high",
        "malware_type": "Virus",
        "managed_app": "no",
        "md5": "cda70ab0130f915723a53a5d9270e7a5",
        "ml_detection": "None",
        "object_type": "File",
        "organization_unit": "",
        "os": "Linux",
        "os_version": "Linux 20.04",
        "page": "hitomi.la/",
        "page_site": "Web Background",
        "policy": "Threat-Malware-Policy-Crest-SRE-Test",
        "policy_id": "342F7551F4D4469E47D7736209486319 2024-07-01 16:28:12.174470",
        "protocol": "HTTPS/1.1",
        "request_id": 2907585389470724608,
        "scanner_result": "malicious",
        "severity": "High",
        "severity_id": 3,
        "sha256": "d330ea88b7a0c2f9190717d8f39a2e3942474c3fefe8b68112e7b93fde0fa9d4",
        "site": "hitomi",
        "src_country": "IN",
        "src_latitude": 23.0276,
        "src_location": "Ahmedabad",
        "src_longitude": 72.5871,
        "src_region": "Gujarat",
        "src_time": "Wed Aug 14 13:48:00 2024",
        "src_timezone": "Asia/Kolkata",
        "src_zipcode": "382350",
        "srcip": "110.226.17.67",
        "timestamp": 1723623535,
        "traffic_type": "Web",
        "transaction_id": 7718454634228557343,
        "true_filetype": "HTML",
        "tss_mode": "inline",
        "type": "nspolicy",
        "ur_normalized": "nipun.brahmbhatt@crestdata.ai",
        "url": "hitomi.la/",
        "user": "nipun.brahmbhatt@crestdata.ai",
        "user_id": "nipun.brahmbhatt@crestdata.ai",
        "userip": "10.50.5.28",
        "record_type": "alert",
        "department": "",
        "scan_time": 0,
        "tss_scan_failed": "",
        "usr_udf_supervisorname": "",
        "instance_id": "",
        "nsdeviceuid": "",
        "modified_date": 0,
        "dst_geoip_src": 0,
        "local_sha256": "",
        "sha1": "",
        "usr_udf_primarydomain": "",
        "fastscan_results": "",
        "sanctioned_instance": "",
        "company": "",
        "user_confidence_index": 0,
        "src_geoip_src": 0,
        "usr_udf_businesssegmentlevel1": "",
        "referer": "",
        "parent_id": "",
        "created_date": 0,
        "usr_udf_businesssegmentlevel2": "",
        "filename": "",
        "from_user": "",
        "file_path": "",
        "manager": "",
        "browser": "",
        "detection_type": "",
        "title": "",
        "object_id": "",
        "mime_type": "",
        "usr_display_name": "",
        "usr_udf_businesssegmentlevel4": "",
        "userPrincipalName": "",
        "appsuite": "",
        "scan_type": "",
        "tss_license": "",
        "managementID": "",
        "usr_status": "",
        "object": "",
        "custom_attr": {},
        "userCountry": "",
        "usr_title": "",
        "usr_udf_businesssegmentlevel3": "",
        "file_name": "",
        "shared_type": "",
        "usr_udf_companyname": "",
        "shared_with": "",
        "tss_fail_reason": "",
        "usr_udf_supervisorid": "",
        "browser_version": "",
        "usr_udf_employeeid": ""
    }
    Get Remediation Alerts

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/alerts/remediation
    Method: GET
    Request Headers

    KeyValue
    Netskope-API-Token<netskope_api_v2_token>
    User-Agentnetskope-ce-6.1.0

    Sample API Response

    {
        "_id": "448ca50ee6142a954d64c577",
        "access_method": "API Connector",
        "acked": "true",
        "action": "alert",
        "activity": "Download",
        "alert": "yes",
        "alert_name": "Remediation alert",
        "alert_type": "Remediation",
        "app": "Clanwilliam Health",
        "appcategory": "Cloud Storage",
        "browser": "unknown",
        "category": "Cloud Storage",
        "cci": 9,
        "ccl": "poor",
        "count": 1,
        "device": "Other",
        "dst_country": "NL",
        "dst_geoip_src": 2,
        "dst_latitude": 52.3759,
        "dst_location": "Amsterdam",
        "dst_longitude": 4.8975,
        "dst_region": "North Holland",
        "dst_zipcode": "1012",
        "dstip": "31.186.239.8",
        "file_size": 118585,
        "file_type": "application/vnd.google-apps.document",
        "instance_id": "netskope.com",
        "md5": "4bf7680195ecaed55e3edabb5d95ca01",
        "object": "VTRapjqhGbaDXqHR",
        "object_type": "File",
        "organization_unit": "netskope.local/Netskope/Active Users/US & International/Full Time",
        "os": "Windows 7.0",
        "policy": "policy_ga34",
        "request_id": "2459149802892628500",
        "site": "Clanwilliam Health",
        "src_country": "NL",
        "src_geoip_src": 2,
        "src_latitude": 52.3759,
        "src_location": "Amsterdam",
        "src_longitude": 4.8975,
        "src_region": "North Holland",
        "src_zipcode": "1012",
        "srcip": "31.186.239.8",
        "timestamp": 1727659690,
        "traffic_type": "CloudApp",
        "type": "nspolicy",
        "ur_normalized": "dte1953ce410-0268t@test.netskope.com",
        "url": "https://drive.google.com/open?id=14WLYNjJxKgEyqIoNAcb57aPGx9_klcxTo3MyjF82rGg",
        "user": "dte1953ce410-0268t@test.netskope.com",
        "managementID": "",
        "from_user": "",
        "os_version": "",
        "app_session_id": 0,
        "malware_severity": "",
        "actions_taken": "",
        "transaction_id": 0,
        "notify_template": "",
        "page": "",
        "browser_session_id": 0,
        "src_time": "",
        "tss_mode": "",
        "managed_app": "",
        "severity": "",
        "nsdeviceuid": "",
        "remediation_profile": "",
        "dlp_profile": "",
        "malware_name": "",
        "endpoints": "",
        "connection_id": 0,
        "policy_id": "",
        "endpoint_count": 0,
        "dst_timezone": "",
        "profile_hits": [],
        "malware_id": "",
        "hostname": "",
        "edr_app": "",
        "device_classification": "",
        "userip": "",
        "appsuite": "",
        "protocol": "",
        "incident_id": 0,
        "src_timezone": "",
        "sanctioned_instance": "",
        "page_site": "",
        "malware_type": "",
        "all_policy_matches": []
    }
    Get Security Assessment Alerts

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/alerts/securityassessment
    Method: GET
    Request Headers

    KeyValue
    Netskope-API-Token<netskope_api_v2_token>
    User-Agentnetskope-ce-6.1.0

    Sample API Response

    {
        "_id": "15bbca35f014e9618efdc629",
        "_insertion_epoch_timestamp": 1727659690,
        "access_method": "API Connector",
        "acked": "false",
        "action": "alert",
        "activity": "Introspection Scan",
        "alert": "yes",
        "alert_name": "security-accessment-alert",
        "alert_type": "Security Assessment",
        "app": "LinkedIn",
        "appcategory": "Cloud Storage",
        "browser": "unknown",
        "category": "Cloud Storage",
        "ccl": "medium",
        "count": 1,
        "device": "Other",
        "dst_country": "FR",
        "dst_geoip_src": 1,
        "dst_latitude": 48.883411,
        "dst_location": "Puteaux",
        "dst_longitude": 2.23894,
        "dst_region": "Ile-de-France",
        "dstip": "193.248.155.211",
        "exposure": "organisation_wide_link",
        "file_lang": "ENGLISH",
        "file_path": "\\/My Drive\\/Clickhouse\\/Tenant Migration across MPs",
        "file_size": 196869,
        "file_type": "application\\/vnd.google-apps.document",
        "instance": "netskope.com",
        "instance_id": "netskope.com",
        "md5": "4bf7680195ecaed55e3edabb5d95ca01",
        "mime_type": "application\\/vnd.google-apps.document",
        "modified": 1613760236,
        "object": "OlWmGNTVpEVLCgWo",
        "object_id": "14WLYNjJxKgEyqIoNAcb57aPGx9_klcxTo3MyjF82rGg",
        "object_type": "File",
        "organization_unit": "netskope.local\\/Netskope\\/Active Users\\/US & International\\/Full Time",
        "os": "unknown",
        "other_categories": [],
        "owner": "foobar",
        "policy": "GDrive Customer metadata shared externally",
        "request_id": "2459149802892628500",
        "sa_profile_id": 1,
        "sa_profile_name": "CRzpqYgDBoKRThmb",
        "sa_rule_id": "icveiWoIMGqmEfUy",
        "sa_rule_name": "RLYnpTzcFeiRcQYr",
        "sa_rule_severity": "High",
        "scan_type": "Ongoing",
        "shared_with": "none",
        "site": "LinkedIn",
        "src_country": "FR",
        "src_geoip_src": 1,
        "src_latitude": 48.883411,
        "src_location": "Puteaux",
        "src_longitude": 2.23894,
        "src_region": "Ile-de-France",
        "srcip": "193.248.155.211",
        "suppression_key": "Tenant Migration across MPs",
        "timestamp": 1727659690,
        "traffic_type": "CloudApp",
        "type": "nspolicy",
        "ur_normalized": "crest_sup_de_202112031049-0@crest.netskope.com",
        "url": "https:\\/\\/drive.google.com\\/open?id=14WLYNjJxKgEyqIoNAcb57aPGx9_klcxTo3MyjF82rGg",
        "user": "crest_sup_de_202112031049-0@crest.netskope.com",
        "usergroup": [],
        "userkey": "crest_sup_de_202112031049-0@crest.netskope.com"
    }
    Get CTEP Alerts

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/alerts/ctep
    Method: GET
    Request Headers

    KeyValue
    Netskope-API-Token<netskope_api_v2_token>
    User-Agentnetskope-ce-6.1.0

    Sample API Response

    {
        "_correlation_id": "d54406dc-5457-4699-8754-c8eece88a804",
        "_event_id": "8de38a44-4ae5-44ac-a097-f9e3ce2aac2a",
        "_forwarded_by": "na",
        "_generator_id": "ad4c77a8-ac83-4493-936c-8d6394038556",
        "_id": "d62273697847e13a884e7562",
        "_insertion_epoch_timestamp": 1727659690,
        "_raw_event_inserted_at": 1676185709059,
        "_seq_id": 117219,
        "_service_identifier": "na",
        "_skip_geoip_lookup": "yes",
        "access_method": "API Connector",
        "acked": "false",
        "action": "block",
        "activity": "Login Successful",
        "alert": "yes",
        "alert_name": "c2",
        "alert_type": "c2",
        "app": "X3host",
        "appcategory": "Cloud Storage",
        "browser": "unknown",
        "category": "Cloud Storage",
        "cci": 16,
        "ccl": "poor",
        "count": 1,
        "device": "11-inch iPad Pro",
        "dst_country": "US",
        "dst_geoip_src": 2,
        "dst_latitude": 45.8234,
        "dst_location": "Boardman",
        "dst_longitude": -119.7257,
        "dst_region": "Oregon",
        "dst_zipcode": "97818",
        "dstip": "52.218.153.131",
        "exposure": "organisation_wide_link",
        "file_lang": "ENGLISH",
        "file_path": "/My Drive/Clickhouse/Tenant Migration across MPs",
        "file_size": 118783,
        "file_type": "application/vnd.google-apps.document",
        "instance": "netskope.com",
        "instance_id": "netskope.com",
        "legal_hold_profile_name": "oejTJocnOabNirPx",
        "lh_custodian_email": "ELGkdoczLAkrQMuq",
        "lh_custodian_name": "iRwQlRYvjwsFlVpg",
        "lh_dest_app": "dOkImPvoHqwfXFaU",
        "lh_dest_instance": "LKMHXgSCmGTmVbZL",
        "lh_fileid": "taAjyAQRSWraghfP",
        "lh_filename": "rsjjtAjqpCcYjaOU",
        "lh_filepath": "IhYDbjTXhzqtUZeD",
        "lh_original_filename": "vWijvCFegHYDULbn",
        "lh_shared": "WCLXYCUEBjqOlWHt",
        "lh_shared_with": "SwUYQdzFHslSQoxr",
        "lh_version": 1,
        "local_sha256": "fd856057ed7703e9b53458c7dbb6a3dc4ce9b957f3b307d81f06bf09c9bd8de3",
        "md5": "4bf7680195ecaed55e3edabb5d95ca01",
        "mime_type": "application/vnd.google-apps.document",
        "modified": 1613760236,
        "object": "OLizsiNCpTCziLEC",
        "object_id": "14WLYNjJxKgEyqIoNAcb57aPGx9_klcxTo3MyjF82rGg",
        "object_type": "File",
        "organization_unit": "netskope.local/Netskope/Active Users/US & International/Full Time",
        "os": "iOS  9.6",
        "other_categories": [],
        "owner": "dte1953ce410-0778t@test.netskope.com",
        "policy": "policy_ga13",
        "request_id": "2459149802892628500",
        "scan_type": "Ongoing",
        "site": "X3host technologies",
        "src_country": "NL",
        "src_geoip_src": 2,
        "src_latitude": 52.3759,
        "src_location": "Amsterdam",
        "src_longitude": 4.8975,
        "src_region": "North Holland",
        "src_zipcode": "1012",
        "srcip": "31.186.239.204",
        "suppression_key": "Tenant Migration across MPs",
        "timestamp": 1727659690,
        "traffic_type": "CloudApp",
        "type": "nspolicy",
        "ur_normalized": "dte1953ce410-0494t@test.netskope.com",
        "url": "https://drive.google.com/open?id=14WLYNjJxKgEyqIoNAcb57aPGx9_klcxTo3MyjF82rGg",
        "user": "dte1953ce410-0494t@test.netskope.com",
        "userkey": "dte1953ce410-0494t@test.netskope.com"
    }
    Get Malsite Alerts

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/alerts/malsite
    Method: GET
    Request Headers

    KeyValue
    Netskope-API-Token<netskope_api_v2_token>
    User-Agentnetskope-ce-6.1.0

    Sample API Response

    {
        "_id": "01f6ca78bec577883076a738",
        "access_method": "Client",
        "acked": "false",
        "action": "block",
        "alert": "yes",
        "alert_name": "bget.ru",
        "alert_type": "malsite",
        "app": "",
        "app_session_id": 4910069257574835437,
        "appcategory": "Security Risk - Compromised/malicious sites",
        "browser_session_id": 1141245448937753175,
        "category": "Security Risk - Compromised/malicious sites",
        "cci": 0,
        "ccl": "unknown",
        "connection_id": 0,
        "count": 1,
        "device": "Linux Device",
        "device_classification": "not configured",
        "dst_country": "RU",
        "dst_latitude": 59.9417,
        "dst_location": "St Petersburg",
        "dst_longitude": 30.3096,
        "dst_region": "St.-Petersburg",
        "dst_timezone": "Europe/Moscow",
        "dst_zipcode": "195213",
        "dstip": "5.101.158.143",
        "dstport": 443,
        "hostname": "ip-172-31-37-148",
        "incident_id": 7989528656047608655,
        "ja3": "07ff1e545ef8ab3fcf8a4dc9272221c2",
        "ja3s": "NotAvailable",
        "malicious": "yes",
        "malsite_category": [
            "Malicious Site"
        ],
        "malsite_country": "RU",
        "malsite_id": "ae7c3ade12353ae7165e9b2f",
        "malsite_ip_host": "5.101.158.143",
        "malsite_latitude": 59.9417,
        "malsite_longitude": 30.3096,
        "malsite_region": "St.-Petersburg",
        "managed_app": "no",
        "notify_template": "block_page.html",
        "organization_unit": "",
        "os": "Linux",
        "os_version": "Linux 22.04",
        "other_categories": [
            "Security Risk",
            "Security Risk - Compromised/malicious sites"
        ],
        "page": "bget.ru/",
        "page_site": "bget",
        "policy": "TestMalsite2",
        "policy_id": "F1AE7109B6FC54098C582D3B0F149521 2024-05-28 13:48:56.784091",
        "protocol": "HTTPS/1.1",
        "request_id": 2851228580036571136,
        "severity_level": "med",
        "severity_level_id": 1,
        "site": "bget",
        "src_country": "US",
        "src_latitude": 39.0469,
        "src_location": "Ashburn",
        "src_longitude": -77.4903,
        "src_region": "Virginia",
        "src_time": "Tue May 28 10:07:00 2024",
        "src_timezone": "America/New_York",
        "src_zipcode": "20149",
        "srcip": "18.209.94.135",
        "telemetry_app": "",
        "threat_match_field": "domain",
        "threat_match_value": "bget.ru",
        "threat_source_id": 1,
        "timestamp": 1716905279,
        "traffic_type": "Web",
        "transaction_id": 7989528656047608655,
        "type": "malsite",
        "ur_normalized": "keshavhazard@gmail.com",
        "url": "bget.ru/",
        "user": "keshavhazard@gmail.com",
        "useragent": "python-requests/2.25.1",
        "userip": "172.31.37.148",
        "record_type": "alert",
        "malsite_reputation": "",
        "object": "",
        "org": "",
        "fromlogs": "",
        "log_file_name": "",
        "req_cnt": 0,
        "browser_version": "",
        "numbytes": 0,
        "department": "",
        "division": "",
        "retro_scan_name": "",
        "sfwder": "",
        "browser": "",
        "custom_attr": {},
        "malsite_confidence": 0,
        "server_bytes": 0,
        "client_bytes": 0,
        "malsite_first_seen": 0,
        "co": "",
        "sAMAccountName": "",
        "src_geoip_src": 0,
        "gateway": "",
        "referer": "",
        "suppression_start_time": 0,
        "resp_cnt": 0,
        "conn_duration": 0,
        "serial": "",
        "malsite_hostility": "",
        "dsthost": "",
        "dst_geoip_src": 0,
        "universal_connector": "",
        "malsite_active": "",
        "from_user": "",
        "object_type": "",
        "suppression_end_time": 0,
        "malsite_last_seen": 0,
        "severity": "",
        "aggregated_user": "",
        "malsite_consecutive": "",
        "appsuite": ""
    }
    Get Policy Alerts

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/alerts/policy
    Method: GET
    Request Headers

    KeyValue
    Netskope-API-Token<netskope_api_v2_token>
    User-Agentnetskope-ce-6.1.0

    Sample API Response

    {
        "_id": "3ceffe626afca6f5d46befb6",
        "access_method": "Client",
        "acked": "false",
        "action": "block",
        "alert": "yes",
        "alert_name": "testprivateapp with2nd opt",
        "alert_type": "policy",
        "app": "[ExtraHop-Demo]",
        "appcategory": "n/a",
        "category": "n/a",
        "cci": 0,
        "ccl": "unknown",
        "client_bytes": 0,
        "client_packets": 0,
        "count": 1,
        "device": "Windows",
        "dsthost": "netskope.atlassian.net",
        "dstip": "",
        "dstport": 443,
        "end_time": "2025-02-28T08:22:47+00:00",
        "hostname": "WIN11-50-12-151",
        "ip_protocol": "TCP",
        "network_session_id": "9452921695540616650",
        "num_sessions": 1,
        "numbytes": 0,
        "organization_unit": "",
        "os": "Windows",
        "os_version": "11.0.22621",
        "other_categories": [],
        "policy": "testprivateapp with2nd opt",
        "protocol": "Http",
        "protocol_port": "TCP:443",
        "publisher_cn": "",
        "publisher_name": "",
        "server_bytes": 0,
        "server_packets": 0,
        "session_duration": 0,
        "site": "netskope.atlassian.net",
        "srcip": "",
        "srcport": 30700,
        "start_time": "2025-02-28T08:22:32+00:00",
        "timestamp": 1740731072,
        "total_packets": 0,
        "traffic_type": "PrivateApp",
        "tunnel_id": "53125",
        "tunnel_type": "NPA",
        "tunnel_up_time": 0,
        "type": "network",
        "ur_normalized": "tanushree.kurup@crestdata.ai",
        "user": "tanushree.kurup@crestdata.ai",
        "userip": "",
        "record_type": "alert",
        "suppression_key": "",
        "app_activity": "",
        "file_type": "",
        "url": "",
        "policy_id": "",
        "custom_connector": "",
        "quarantine_profile": "",
        "q_original_shared": "",
        "file_path": "",
        "profile_emails": [],
        "referer": "",
        "md5": "",
        "redirect_url": "",
        "page_site": "",
        "malware_name": "",
        "suppression_end_time": 0,
        "user_id": "",
        "distinguishedName": "",
        "severity": "",
        "src_timezone": "",
        "tss_mode": "",
        "managed_app": "",
        "tss_fail_reason": "",
        "src_geoip_src": 0,
        "owner": "",
        "aggregated_user": "",
        "group": "",
        "total_collaborator_count": 0,
        "userCountry": "",
        "browser": "",
        "to_user": "",
        "from_object": "",
        "ext_labels": [],
        "shared_with": "",
        "useragent": "",
        "sessionid": "",
        "network": "",
        "malicious": "",
        "quarantine_file_id": "",
        "appsuite": "",
        "remediation_profile": "",
        "universal_connector": "",
        "mime_type": "",
        "browser_version": "",
        "src_zipcode": "",
        "access_key_id": "",
        "src_latitude": 0.0,
        "malware_type": "",
        "dynamic_classification": "",
        "src_region": "",
        "q_original_version": "",
        "instance_id": "",
        "message_id": "",
        "sfwder": "",
        "q_admin": "",
        "q_app": "",
        "object_type": "",
        "log_file_name": "",
        "malware_severity": "",
        "retro_scan_name": "",
        "displayName": "",
        "justification_reason": "",
        "q_instance": "",
        "src_location": "",
        "gateway": "",
        "forward_to_proxy_xau": "",
        "justification_type": "",
        "smtp_to": [],
        "app_session_id": 0,
        "request_id": 0,
        "app_scopes": "",
        "parent_id": "",
        "file_category": "",
        "file_id": "",
        "dlp_profile": "",
        "nsdeviceuid": "",
        "risk_level": "",
        "encrypt_failure": "",
        "quarantine_file_name": "",
        "src_longitude": 0.0,
        "file_size": 0,
        "org": "",
        "user_tmp": "",
        "activity_status": "",
        "threat_match_value": "",
        "malsite_category": [],
        "dst_timezone": "",
        "all_policy_matches": [],
        "incident_id": 0,
        "orignal_file_path": "",
        "object_id": "",
        "act_user": "",
        "http_status": "",
        "dst_country": "",
        "from_user": "",
        "req_cnt": 0,
        "transaction_id": 0,
        "browser_session_id": 0,
        "sanctioned_instance": "",
        "from_storage": "",
        "tss-mode": "",
        "cc": "",
        "activity": "",
        "sAMAccountName": "",
        "scan_type": "",
        "serial": "",
        "src_time": "",
        "managementID": "",
        "object": "",
        "q_original_filepath": "",
        "custom_attr": {},
        "shared_domains": "",
        "q_original_filename": "",
        "notify_template": "",
        "connection_id": 0,
        "telemetry_app": "",
        "threat_source_id": 0,
        "user_confidence_index": 0,
        "TSS-scan": "",
        "internal_collaborator_count": 0,
        "last_name": "",
        "mail": "",
        "sAMAccountType": "",
        "memberOf": "",
        "smtp_status": "",
        "Title": "",
        "dst_location": "",
        "bcc": "",
        "dst_geoip_src": 0,
        "exposure": "",
        "activity_type": "",
        "dlp_fail_reason": "",
        "dst_zipcode": "",
        "message_size": 0,
        "suppression_start_time": 0,
        "trust_computer_checked": "",
        "device_classification": "",
        "instance": "",
        "to_storage": "",
        "dst_latitude": 0.0,
        "division": "",
        "object_count": 0,
        "to_object": "",
        "modified": 0,
        "sender": "",
        "dst_region": "",
        "page": "",
        "conn_duration": 0,
        "two_factor_auth": "",
        "dst_longitude": 0.0,
        "data_type": "",
        "quarantine_profile_id": "",
        "malware_id": "",
        "manager": "",
        "src_country": "",
        "event_type": "",
        "external_collaborator_count": 0,
        "resp_cnt": 0,
        "threat_match_field": "",
        "tss_scan_failed": "",
        "dlp_scan_failed": "",
        "sha256": ""
    }
    Get Quarantine Alerts

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/alerts/quarantine
    Method: GET
    Request Headers

    KeyValue
    Netskope-API-Token<netskope_api_v2_token>
    User-Agentnetskope-ce-6.1.0

    Sample API Response

    {
        "_id": "63d6a681f0d64a6f41cc084c",
        "_insertion_epoch_timestamp": 1727659690,
        "access_method": "API Connector",
        "acked": "false",
        "action": "quarantine-sahil",
        "activity": "Login Successful",
        "alert": "yes",
        "alert_name": "quarantine-alert",
        "alert_type": "quarantine",
        "app": "Dropbox",
        "appcategory": "Cloud Storage",
        "browser": "unknown",
        "category": "Cloud Storage",
        "cci": 81,
        "ccl": "high",
        "count": 1,
        "device": "Other",
        "dst_country": "US",
        "dst_geoip_src": 2,
        "dst_latitude": 33.1432,
        "dst_location": "San Marcos",
        "dst_longitude": -117.1666,
        "dst_region": "California",
        "dst_zipcode": "92069",
        "dstip": "98.176.143.16",
        "exposure": "organisation_wide_link",
        "file_lang": "ENGLISH",
        "file_path": "\\/My Drive\\/Clickhouse\\/Tenant Migration across MPs",
        "file_size": 196869,
        "file_type": "application\\/vnd.google-apps.document",
        "instance": "netskope.com",
        "instance_id": "netskope.com",
        "md5": "4bf7680195ecaed55e3edabb5d95ca01",
        "mime_type": "application\\/vnd.google-apps.document",
        "modified": 1613760236,
        "object": "weclTNVzKoULFCYX",
        "object_id": "14WLYNjJxKgEyqIoNAcb57aPGx9_klcxTo3MyjF82rGg",
        "object_type": "File",
        "organization_unit": "netskope.local\\/Netskope\\/Active Users\\/US & International\\/Full Time",
        "os": "unknown",
        "other_categories": [],
        "owner": "foobar",
        "policy": "GDrive Customer metadata shared externally",
        "q_admin": "KgBNclCNvMfSfwAe",
        "q_app": "Box",
        "q_instance": "IXlwfxAfRQMyUbso",
        "q_original_filename": "huSgEkeGhFjPDLhS",
        "q_original_filepath": "oJmMLhuvhIyXlarC",
        "q_original_shared": "private",
        "q_original_version": "1",
        "q_shared_with": "PqtCjqtPLVOOFkWk",
        "quarantine_action_reason": "TuJbfomareEgmNNT",
        "quarantine_app": "Amazon S3",
        "quarantine_failure": "mDsCCrKldEQdhrEF",
        "quarantine_file_id": "jeCCFYBKuaBggvol",
        "quarantine_file_name": "GEXNzZEGpZFQAuUv",
        "quarantine_profile": "fQECcfyXhgGUOJSO",
        "quarantine_profile_id": "xfFlQTBQWxjnIsXZ",
        "request_id": "2459149802892628500",
        "scan_type": "Ongoing",
        "shared_with": "none",
        "site": "Dropbox",
        "src_country": "DE",
        "src_geoip_src": 2,
        "src_latitude": 50.1188,
        "src_location": "Frankfurt am Main",
        "src_longitude": 8.6843,
        "src_region": "Hesse",
        "src_zipcode": "60313",
        "srcip": "8.39.144.84",
        "suppression_key": "Tenant Migration across MPs",
        "timestamp": 1727659690,
        "traffic_type": "CloudApp",
        "type": "nspolicy",
        "ur_normalized": "crest_sup_de_202112031049-0@crest.netskope.com",
        "url": "https:\\/\\/drive.google.com\\/open?id=14WLYNjJxKgEyqIoNAcb57aPGx9_klcxTo3MyjF82rGg",
        "user": "crest_sup_de_202112031049-0@crest.netskope.com",
        "usergroup": [],
        "userkey": "crest_sup_de_202112031049-0@crest.netskope.com"
    }
    Get UBA Alerts

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/alerts/uba
    Method: GET
    Request Headers

    KeyValue
    Netskope-API-Token<netskope_api_v2_token>
    User-Agentnetskope-ce-6.1.0

    Sample API Response

    {
        "_id": "b7dce8f570123bdd868a8315",
        "access_method": "UCI Impact API",
        "acked": "false",
        "action": "anomaly_detection",
        "activity": "ActivityForUciImpactAPI",
        "alert": "yes",
        "alert_id": "505464b05529c82e34d31970",
        "alert_name": "External alert from Netskope due to Risky User",
        "alert_type": "uba",
        "anomaly_type": "Fact",
        "app": "",
        "appcategory": "n/a",
        "category": "n/a",
        "cci": 0,
        "ccl": "unknown",
        "count": 1,
        "createdTime": "2025-02-24 08:15:55.461000",
        "device": "Other",
        "event_type": "uba_analytics",
        "instance_id": "",
        "organization_unit": "",
        "policy": "External alert received via REST API",
        "score": 1,
        "severity": "informational",
        "src_country": "IN",
        "src_geoip_src": 2,
        "src_latitude": 23.0276,
        "src_location": "Ahmedabad",
        "src_longitude": 72.5871,
        "src_region": "Gujarat",
        "src_zipcode": "380009",
        "srcip": "122.170.162.148",
        "timestamp": 1740384954,
        "type": "nspolicy",
        "ur_normalized": "tanushree.kurup@crestdata.ai",
        "user": "tanushree.kurup@crestdata.ai",
        "userkey": "tanushree.kurup@crestdata.ai",
        "windowId": 1740355200000,
        "record_type": "alert",
        "last_device": "",
        "surhn": "",
        "policy_id": "",
        "uba_ap1": "",
        "evt_src_chnl": "",
        "all_policy_matches": [],
        "threshold": 0,
        "web_universal_connector": "",
        "user_category": "",
        "managementID": "",
        "division": "",
        "download_app": "",
        "user_id": "",
        "dst_longitude": 0.0,
        "audit_type": "",
        "object_count": 0,
        "policy_name": "",
        "activity_status": "",
        "group": "",
        "act_user": "",
        "referer": "",
        "connection_id": 0,
        "app_category": "",
        "bin_timestamp": 0,
        "hostname": "",
        "app_activity": "",
        "md5": "",
        "risk_level_id": 0,
        "suppression_end_time": 0,
        "protocol": "",
        "request_type": "",
        "request_id": 0,
        "app_session_id": 0,
        "User_SPACE_Id": "",
        "user_name": "",
        "last_timestamp": 0,
        "netskope_activity": "",
        "dst_geoip_src": 0,
        "tss_scan_failed": "",
        "loginurl": "",
        "threshold_time": 0,
        "risk_level": "",
        "managed_app": "",
        "browser_version": "",
        "file_category": "",
        "from_user_category": "",
        "page": "",
        "last_location": "",
        "url": "",
        "uba_ap2": "",
        "sanctioned_instance": "",
        "object_id": "",
        "dst_timezone": "",
        "custom_attr": {},
        "to_object": "",
        "dst_country": "",
        "traffic_type": "",
        "telemetry_app": "",
        "page_site": "",
        "file_size": 0,
        "scopes": [],
        "anomalyData": {},
        "os": "",
        "audit_category": "",
        "tss_fail_reason": "",
        "userip": "",
        "last_app": "",
        "incident_id": 0,
        "suppression_start_time": 0,
        "dst_zipcode": "",
        "dstip": "",
        "policy_actions": [],
        "browser": "",
        "src_time": "",
        "sAMAccountName": "",
        "two_factor_auth": "",
        "uba_inst2": "",
        "site": "",
        "displayName": "",
        "sha256": "",
        "object": "",
        "last_country": "",
        "to_user": "",
        "object_type": "",
        "manager": "",
        "last_region": "",
        "dst_region": "",
        "dst_latitude": 0.0,
        "shared_credential_user": "",
        "file_type": "",
        "tss_mode": "",
        "appsuite": "",
        "device_classification": "",
        "logintype": "",
        "AccountType": "",
        "os_version": "",
        "parent_id": "",
        "TSS-scan": "",
        "user_role": "",
        "dst_location": "",
        "to_user_category": "",
        "user_confidence_index": 0,
        "mail": "",
        "browser_session_id": 0,
        "src_timezone": "",
        "useragent": "",
        "employeeType": "",
        "from_user": "",
        "uba_inst1": "",
        "User_SPACE_Name": "",
        "userPrincipalName": "",
        "transaction_id": 0,
        "distinguishedName": "",
        "profile_id": ""
    }
    Get Watchlist Alerts

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/alerts/watchlist
    Method: GET
    Request Headers

    KeyValue
    Netskope-API-Token<netskope_api_v2_token>
    User-Agentnetskope-ce-6.1.0

    Sample API Response

    {
        "_id": "ad921f96aaf7dc5b6fe5d628",
        "access_method": "API Connector",
        "acked": "true",
        "activity": "Upload",
        "alert": "yes",
        "alert_name": "watchlist fired",
        "alert_type": "watchlist",
        "app": "Amazon App Suite",
        "appcategory": "Cloud Storage",
        "browser": "unknown",
        "category": "Cloud Storage",
        "cci": 89,
        "ccl": "high",
        "count": 1,
        "device": "Other",
        "dst_country": "IN",
        "dst_geoip_src": 2,
        "dst_latitude": 19.0748,
        "dst_location": "Mumbai",
        "dst_longitude": 72.8856,
        "dst_region": "Maharashtra",
        "dst_zipcode": "400072",
        "dstip": "182.75.130.70",
        "exposure": "organisation_wide_link",
        "file_lang": "ENGLISH",
        "file_path": "/My Drive/Clickhouse/Tenant Migration across MPs",
        "file_size": 119268,
        "file_type": "application/vnd.google-apps.document",
        "instance": "netskope.com",
        "instance_id": "netskope.com",
        "local_sha256": "aa477dd147d603cd0bd65b6dfb09021654e212aa3200ceb03e3a1e1d0fb37fdb",
        "md5": "4bf7680195ecaed55e3edabb5d95ca01",
        "mime_type": "application/vnd.google-apps.document",
        "modified": 1613760236,
        "object": "uVwtiXcnOjCdpJHt",
        "object_id": "14WLYNjJxKgEyqIoNAcb57aPGx9_klcxTo3MyjF82rGg",
        "object_type": "File",
        "organization_unit": "netskope.local/Netskope/Active Users/US & International/Full Time",
        "os": "Windows 8.0",
        "owner": "dte1953ce410-0545t@test.netskope.com",
        "policy": "policy_ga26",
        "request_id": "2459149802892628500",
        "scan_type": "Ongoing",
        "site": "Amazon App Suite",
        "src_country": "DE",
        "src_geoip_src": 2,
        "src_latitude": 50.1188,
        "src_location": "Frankfurt am Main",
        "src_longitude": 8.6843,
        "src_region": "Hesse",
        "src_zipcode": "60313",
        "srcip": "8.39.144.84",
        "suppression_key": "Tenant Migration across MPs",
        "timestamp": 1727659690,
        "traffic_type": "CloudApp",
        "type": "nspolicy",
        "ur_normalized": "dte1953ce410-0191t@test.netskope.com",
        "url": "https://drive.google.com/open?id=14WLYNjJxKgEyqIoNAcb57aPGx9_klcxTo3MyjF82rGg",
        "user": "dte1953ce410-0191t@test.netskope.com",
        "userkey": "dte1953ce410-0191t@test.netskope.com",
        "dst_timezone": "",
        "two_factor_auth": "",
        "dlp_fail_reason": "",
        "title": "",
        "conn_duration": 0,
        "shared_domains": "",
        "user_id": "",
        "notify_template": "",
        "severity_id": 0,
        "TSS-scan": "",
        "universal_connector": "",
        "to_user_category": "",
        "web_url": "",
        "severity": "",
        "netskope_activity": "",
        "malware_severity": "",
        "dlp_is_unique_count": "",
        "sAMAccountName": "",
        "hostname": "",
        "sanctioned_instance": "",
        "object_count": 0,
        "dlp_rule": "",
        "protocol": "",
        "file_id": "",
        "audit_type": "",
        "internal_collaborator_count": 0,
        "dlp_scan_failed": "",
        "appsuite": "",
        "dlp_rule_severity": "",
        "telemetry_app": "",
        "to_user": "",
        "true_obj_category": "",
        "useragent": "",
        "shared_with": "",
        "justification_reason": "",
        "dlp_parent_id": 0,
        "referer": "",
        "src_timezone": "",
        "connection_id": 0,
        "app_session_id": 0,
        "from_user_category": "",
        "client_bytes": 0,
        "malware_name": "",
        "total_collaborator_count": 0,
        "policy_id": "",
        "workspace": "",
        "data_type": "",
        "dlp_profile": "",
        "act_user": "",
        "malware_profile": "",
        "file_name": "",
        "fromlogs": "",
        "ml_detection": "",
        "app_activity": "",
        "malware_id": "",
        "dstport": 0,
        "transaction_id": 0,
        "detection_engine": "",
        "to_storage": "",
        "parent_id": "",
        "managed_app": "",
        "external_collaborator_count": 0,
        "nsdeviceuid": "",
        "tss_fail_reason": "",
        "managementID": "",
        "workspace_id": "",
        "true_obj_type": "",
        "justification_type": "",
        "aggregated_user": "",
        "network": "",
        "org": "",
        "page_site": "",
        "userPrincipalName": "",
        "tss_mode": "",
        "suppression_end_time": 0,
        "true_type_id": 0,
        "server_bytes": 0,
        "manager": "",
        "suppression_start_time": 0,
        "file_category": "",
        "app_name": "",
        "audit_category": "",
        "incident_id": 0,
        "serial": "",
        "resp_cnt": 0,
        "browser_version": "",
        "all_policy_matches": [],
        "enterprise": "",
        "numbytes": 0,
        "device_classification": "",
        "from_object": "",
        "dlp_rule_count": 0,
        "dsthost": "",
        "src_time": "",
        "user_category": "",
        "browser_session_id": 0,
        "sfwder": "",
        "scanner_result": "",
        "dlp_file": "",
        "os_version": "",
        "to_object": "",
        "malware_type": "",
        "log_file_name": "",
        "web_universal_connector": "",
        "enterprise_id": "",
        "dlp_incident_id": 0,
        "from_user": "",
        "userip": "",
        "page": "",
        "req_cnt": 0,
        "from_storage": "",
        "tss_scan_failed": "",
        "local_md5": ""
    }
    Get Device Alerts

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/alerts/device
    Method: GET
    Request Headers

    KeyValue
    Netskope-API-Token<netskope_api_v2_token>
    User-Agentnetskope-ce-6.1.0

    Sample API Response

    {
        "_id": "983681ec8804b23e77c2c292",
        "access_method": "Endpoint",
        "action": "block",
        "activity": "Insert",
        "alert": "yes",
        "alert_name": "TestBlock",
        "alert_type": "Device",
        "computer_name": "N49J4M9T3C",
        "count": 1,
        "device_classification": "not configured",
        "organization_unit": "",
        "os": "macOS",
        "os_details": "Mac OS X Sonoma 14.3.1 arm64",
        "policy": "TestBlock",
        "policy_action": "block",
        "policy_name_enforced": "TestBlock",
        "timestamp": 1720005433,
        "traffic_type": "",
        "type": "endpoint",
        "ur_normalized": "kmaheshwari@netskope.com",
        "usb_device_id": "USB\\VID_03f0&PID_1985&REV_0110",
        "usb_device_name": "USB Flash Drive",
        "usb_device_sn": "070D2C206FCFA597",
        "usb_device_type": "usb mass storage",
        "usb_product_id": "6533",
        "usb_vendor_id": "HP",
        "user": "kmaheshwari@netskope.com",
        "userkey": "kmaheshwari@netskope.com",
        "record_type": "alert",
        "connection_type": "",
        "driver": "",
        "os_user_name": "",
        "usb_is_encrypted": false,
        "location": "",
        "custom_attr": {}
    }
    Get Content Alerts

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/alerts/content
    Method: GET
    Request Headers

    KeyValue
    Netskope-API-Token<netskope_api_v2_token>
    User-Agentnetskope-ce-6.1.0

    Sample API Response

    {
        "_id": "3f14cdb17c8385f9a6acfab4",
        "access_method": "Endpoint",
        "action": "block",
        "activity": "Create",
        "alert": "yes",
        "alert_name": "mmm1",
        "alert_type": "Content",
        "app": "DesktopServicesHelper",
        "computer_name": "N49J4M9T3C",
        "count": 1,
        "destination_file_directory": "/Volumes/KALI LINUX",
        "destination_file_name": "urls.txt",
        "destination_file_path": "/Volumes/KALI LINUX/urls.txt",
        "device_classification": "not configured",
        "dlp_incident_id": 8329186087212438192,
        "dlp_profile": "DLPTest",
        "file_size": 52483,
        "file_type": "Plain Text file",
        "incident_id": 8329186087212438192,
        "md5": "da3faaff0b406f6aa4685aee47ece41c",
        "organization_unit": "",
        "os": "macOS",
        "os_details": "Mac OS X Sonoma 14.3.1 arm64",
        "os_user_name": "kmaheshwari",
        "pid": "0",
        "policy": "mmm1",
        "policy_action": "block",
        "policy_name_enforced": "mmm1",
        "process_name": "DesktopServicesHelper",
        "process_path": "/System/Library/PrivateFrameworks/DesktopServicesPriv.framework/Versions/A/Resources",
        "sha256": "23a129d56da1579a68862808a22b7b3e1d64682cc7d4c725fdc8a8c7980310b6",
        "site": "DesktopServicesHelper",
        "timestamp": 1719993896,
        "traffic_type": "",
        "type": "endpoint",
        "ur_normalized": "kmaheshwari@netskope.com",
        "usb_device_type": "usb mass storage",
        "user": "kmaheshwari@netskope.com",
        "userkey": "kmaheshwari@netskope.com",
        "record_type": "alert",
        "custom_attr": {},
        "process_cert_subject": "",
        "device": ""
    }
    Page Events

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/events/page
    Method: GET
    Request Headers

    KeyValue
    Netskope-API-Token<netskope_api_v2_token>
    User-Agentnetskope-ce-6.1.0

    Sample API Response

    {
        "_id": "56758f371f4e65c4049d423e",
        "access_method": "Client",
        "app": "Microsoft Accounts",
        "appcategory": "Application Suite",
        "bypass_reason": "SSL Do Not Decrypt Bypass Policy Matched",
        "bypass_traffic": "yes",
        "category": "Application Suite",
        "cci": 84,
        "ccl": "high",
        "connection_id": 0,
        "count": 1,
        "domain": "ecs.office.com",
        "dst_country": "US",
        "dst_latitude": 47.6722,
        "dst_location": "Redmond",
        "dst_longitude": -122.1257,
        "dst_region": "Washington",
        "dst_timezone": "America/Los_Angeles",
        "dst_zipcode": "98073",
        "dstip": "52.123.128.14",
        "dstport": 443,
        "netskope_pop": "IN-BOM2",
        "organization_unit": "",
        "os_version": "Windows NT 11.0",
        "other_categories": [
            "Technology",
            "Application Suite"
        ],
        "page": "ecs.office.com",
        "policy": "Default Microsoft appsuite SSL do not decrypt rule",
        "request_id": 3051109095898995457,
        "site": "Microsoft Office 365 Suite",
        "src_country": "IN",
        "src_latitude": 21.7003,
        "src_location": "Bharūch",
        "src_longitude": 72.9782,
        "src_region": "Gujarat",
        "src_time": "Fri Feb 28 14:26:08 2025",
        "src_timezone": "Asia/Kolkata",
        "src_zipcode": "392012",
        "srcip": "103.108.207.58",
        "ssl_decrypt_policy": "yes",
        "timestamp": 1740732961,
        "traffic_type": "CloudApp",
        "transaction_id": 0,
        "type": "connection",
        "ur_normalized": "tanushree.kurup@crestdata.ai",
        "url": "ecs.office.com",
        "user": "tanushree.kurup@crestdata.ai",
        "user_generated": "yes",
        "userip": "10.50.12.151",
        "userkey": "tanushree.kurup@crestdata.ai",
        "record_type": "page",
        "useragent": "",
        "CononicalName": "",
        "forward_to_proxy_profile": "",
        "http_transaction_count": 0,
        "resp_content_type": "",
        "org": "",
        "browser_version": "",
        "conn_starttime": 0,
        "os": "",
        "network": "",
        "device": "",
        "req_cnt": 0,
        "src_geoip_src": 0,
        "conn_endtime": 0,
        "dst_geoip_src": 0,
        "hostname": "",
        "client_bytes": 0,
        "dsthost": "",
        "userPrincipalName": "",
        "numbytes": 0,
        "fromlogs": "",
        "rbi_template_name": "",
        "resp_cnt": 0,
        "browser_session_id": 0,
        "resp_content_len": 0,
        "server_bytes": 0,
        "forward_to_proxy_xau": "",
        "conn_duration": 0,
        "serial": "",
        "sAMAccountName": "",
        "log_file_name": "",
        "rbi_template_id": "",
        "dynamic_classification": "",
        "browser": "",
        "severity": "",
        "suppression_end_time": 0,
        "custom_attr": {},
        "action": "",
        "suppression_start_time": 0,
        "sessionid": "",
        "protocol": "",
        "app_session_id": 0
    }
    Get Application Events

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/events/application
    Method: GET
    Request Headers

    KeyValue
    Netskope-API-Token<netskope_api_v2_token>
    User-Agentnetskope-ce-6.1.0

    Sample API Response

    {
        "_id": "5af424a2871523b6e13f853f",
        "access_method": "Client",
        "activity": "Download",
        "alert": "no",
        "app": "ContentSquare",
        "app_session_id": 8320876311700568950,
        "appcategory": "Web Analytics",
        "browser": "Edge",
        "browser_session_id": 5471226135867547944,
        "browser_version": "133.0.0.0",
        "category": "Web Analytics",
        "cci": 60,
        "ccl": "medium",
        "connection_id": 0,
        "count": 1,
        "device": "Windows Device",
        "device_classification": "not configured",
        "dst_country": "IE",
        "dst_latitude": 53.3382,
        "dst_location": "Dublin",
        "dst_longitude": -6.2591,
        "dst_region": "Leinster",
        "dst_timezone": "Europe/Dublin",
        "dst_zipcode": "D02",
        "dstip": "52.48.68.180",
        "dstport": 443,
        "hostname": "WIN11-50-12-151",
        "ja3": "261219d3f4c7b45e9e6014a0084dc181",
        "ja3s": "f4febc55ea12b31ae17cfb7e614afda8",
        "managed_app": "no",
        "netskope_pop": "IN-BOM2",
        "object": "pageview",
        "object_type": "File",
        "organization_unit": "",
        "os": "Windows 11",
        "os_version": "Windows NT 11.0",
        "other_categories": [
            "Content Server",
            "Web Analytics"
        ],
        "page": "c.contentsquare.net/pageview",
        "page_site": "contentsquare",
        "policy_id": "8467252215149297331 2025-02-19 10:04:24.766887",
        "protocol": "HTTPS/1.1",
        "request_id": 3045298505167235584,
        "severity": "unknown",
        "site": "ContentSquare",
        "src_country": "IN",
        "src_latitude": 23.0276,
        "src_location": "Ahmedabad",
        "src_longitude": 72.5871,
        "src_region": "Gujarat",
        "src_time": "Thu Feb 20 14:00:08 2025",
        "src_timezone": "Asia/Kolkata",
        "src_zipcode": "380006",
        "srcip": "182.69.215.65",
        "telemetry_app": "",
        "timestamp": 1740040217,
        "traffic_type": "CloudApp",
        "transaction_id": 1737423402988911503,
        "type": "nspolicy",
        "universal_connector": "yes",
        "ur_normalized": "tanushree.kurup@crestdata.ai",
        "url": "c.contentsquare.net/pageview",
        "user": "tanushree.kurup@crestdata.ai",
        "useragent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0",
        "userip": "10.50.12.151",
        "userkey": "tanushree.kurup@crestdata.ai",
        "record_type": "application",
        "suppression_key": "",
        "app_activity": "",
        "file_type": "",
        "dlp_incident_id": 0,
        "custom_connector": "",
        "file_path": "",
        "referer": "",
        "md5": "",
        "suppression_end_time": 0,
        "user_id": "",
        "tss_mode": "",
        "channel_id": "",
        "dlp_rule_count": 0,
        "web_universal_connector": "",
        "tss_fail_reason": "",
        "src_geoip_src": 0,
        "owner": "",
        "alert_type": "",
        "total_collaborator_count": 0,
        "to_user": "",
        "ext_labels": [],
        "shared_with": "",
        "sessionid": "",
        "client_bytes": 0,
        "appsuite": "",
        "mime_type": "",
        "dlp_rule_severity": "",
        "workspace_id": "",
        "instance_id": "",
        "logintype": "",
        "policy": "",
        "log_file_name": "",
        "retro_scan_name": "",
        "justification_reason": "",
        "user_category": "",
        "netskope_activity": "",
        "justification_type": "",
        "smtp_to": [],
        "parent_id": "",
        "nsdeviceuid": "",
        "dlp_profile": "",
        "file_lang": "",
        "file_size": 0,
        "userPrincipalName": "",
        "org": "",
        "audit_type": "",
        "title": "",
        "orignal_file_path": "",
        "object_id": "",
        "dsthost": "",
        "from_user": "",
        "req_cnt": 0,
        "sanctioned_instance": "",
        "dlp_rule": "",
        "loginurl": "",
        "scan_type": "",
        "sAMAccountName": "",
        "serial": "",
        "managementID": "",
        "custom_attr": {},
        "from_user_category": "",
        "notify_template": "",
        "dlp_parent_id": 0,
        "user_confidence_index": 0,
        "internal_collaborator_count": 0,
        "dlp_unique_count": 0,
        "dlp_mail_parent_id": "",
        "true_obj_category": "",
        "dst_geoip_src": 0,
        "exposure": "",
        "dlp_is_unique_count": "",
        "numbytes": 0,
        "dlp_fail_reason": "",
        "suppression_start_time": 0,
        "audit_category": "",
        "true_obj_type": "",
        "data_center": "",
        "instance": "",
        "server_bytes": 0,
        "modified": 0,
        "action": "",
        "conn_duration": 0,
        "data_type": "",
        "fromlogs": "",
        "resp_cnt": 0,
        "workspace": "",
        "dlp_file": "",
        "CononicalName": "",
        "tss_scan_failed": "",
        "dlp_scan_failed": "",
        "sha256": ""
    }
    Get Audit Events

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/events/audit
    Method: GET
    Request Headers

    KeyValue
    Netskope-API-Token<netskope_api_v2_token>
    User-Agentnetskope-ce-6.1.0

    Sample API Response

    {
        "audit_log_event": "Rest API V2 Call",
        "severity_level": 2,
        "supporting_data": {
            "data_type": "policy",
            "data_values": [
                "200",
                "POST",
                "/api/v2/policy/urllist/deploy",
                "trid=22f0b0dfb2b8d75d27aa528ff6040e5d.1740723551"
            ]
        },
        "timestamp": 1740723551,
        "type": "admin_audit_logs",
        "user": "DO-NOT-DELETE",
        "organization_unit": "",
        "ur_normalized": "do-not-delete",
        "count": 1,
        "_id": "074fdfdb6974f8960bfaede9",
        "record_type": "audit",
        "sAMAccountName": "",
        "details": [],
        "ccl": "",
        "userPrincipalName": ""
    }
    Get Infrastructure Events

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/events/infrastructure
    Method: GET
    Request Headers

    KeyValue
    Netskope-API-Token<netskope_api_v2_token>
    User-Agentnetskope-ce-6.1.0

    Sample API Response

    {
        "timestamp": 1727659690,
        "severity": "high",
        "alarm_name": "No_events_from_device",
        "device_name": "panw-dpop-1",
        "metric_value": 43831789,
        "alarm_description": "Events from 仕事 device not received in the last 24 hours",
        "serial": "FF00A7BFFA4E6165E",
        "_insertion_epoch_timestamp": 1727659690,
        "supporting_data": "",
        "_id": "613ee55ec9d868fc47654a73"
    }
    Get Network Events

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/events/network
    Method: GET
    Request Headers

    KeyValue
    Netskope-API-Token<netskope_api_v2_token>
    User-Agentnetskope-ce-6.1.0

    Sample API Response

    {
        "_id": "f67629951b42c8e556062456",
        "access_method": "Client",
        "action": "block",
        "app": "Domain Name Service (DNS)",
        "appcategory": "Shopping",
        "category": "Shopping",
        "cci": 0,
        "ccl": "unknown",
        "client_bytes": 0,
        "client_packets": 0,
        "count": 1,
        "device": "Other",
        "domain": "",
        "dst_geoip_src": 2,
        "dsthost": "",
        "dstip": "10.50.1.16",
        "dstport": 5353,
        "end_time": "2025-02-28T09:34:08+00:00",
        "flow_status": "close",
        "ip_protocol": "UDP",
        "numbytes": 0,
        "organization_unit": "",
        "os": "Windows NT 11.0",
        "policy": "default",
        "publisher_name": "",
        "server_bytes": 0,
        "server_packets": 0,
        "session_duration": 0,
        "site": "dns",
        "src_country": "IN",
        "src_geoip_src": 2,
        "src_latitude": 21.7003,
        "src_location": "Bharūch",
        "src_longitude": 72.9782,
        "src_region": "Gujarat",
        "src_zipcode": "392011",
        "srcip": "103.108.207.58",
        "srcport": 5353,
        "start_time": "2025-02-28T09:34:08+00:00",
        "timestamp": 1740735248,
        "total_packets": 0,
        "traffic_type": "non-web",
        "tunnel_id": "1138033360427841",
        "type": "network",
        "ur_normalized": "tanushree.kurup@crestdata.ai",
        "user": "tanushree.kurup@crestdata.ai",
        "userip": "10.50.12.151",
        "userkey": "tanushree.kurup@crestdata.ai",
        "record_type": "network",
        "qdomain": "",
        "dst_region": "",
        "userPrincipalName": "",
        "dst_country": "",
        "tunnel_type": "",
        "dst_zipcode": "",
        "num_sessions": 0,
        "domain_ip": "",
        "dst_longitude": 0.0,
        "protocol": "",
        "tunnel_up_time": 0,
        "protocol_port": "",
        "network_session_id": "",
        "os_version": "",
        "dst_latitude": 0.0,
        "sAMAccountName": "",
        "hostname": "",
        "custom_attr": {},
        "publisher_cn": "",
        "dst_location": ""
    }
    Get Incident Events

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/events/incident
    Method: GET
    Request Headers

    KeyValue
    Netskope-API-Token<netskope_api_v2_token>
    User-Agentnetskope-ce-6.1.0

    Sample API Response

    {
        "_id": "6d462e0db470c7247e75322fd380031271d1be18db9d707ef6f3affc792f11b1",
        "access_method": "Endpoint Protection",
        "acting_user": "kmaheshwari@netskope.com",
        "activity": "Create",
        "app": "DesktopServicesHelper",
        "assignee": "None",
        "dlp_incident_id": 7268524954762607217,
        "dlp_match_info": [
            {
                "dlp_action": "block",
                "dlp_forensic_id": 1711868037568704387,
                "dlp_policy": "mmm1",
                "dlp_profile_name": "DLPTest",
                "dlp_rules": []
            }
        ],
        "file_path": "/Volumes/KALI LINUX/urls.txt",
        "file_size": 52483,
        "file_type": "Plain Text file",
        "md5": "da3faaff0b406f6aa4685aee47ece41c",
        "object": "urls.txt",
        "object_id": "hash_kmaheshwari@netskope.com_da3faaff0b406f6aa4685aee47ece41c_7b4a2e1f194ccb4e8eca958a472bfe3c3741d7a6",
        "severity": "Low",
        "status": "new",
        "timestamp": 1719993903,
        "title": "urls.txt",
        "user": "kmaheshwari@netskope.com",
        "record_type": "incident",
        "instance": "",
        "src_location": "",
        "app_session_id": 0,
        "zip_file_id": "",
        "connection_id": 0,
        "destination_site": "",
        "to_user": "",
        "latest_incident_id": 0,
        "from_user": "",
        "site": "",
        "dst_location": "",
        "inline_dlp_match_info": [],
        "destination_instance_id": "",
        "instance_id": "",
        "channel": "",
        "original_file_snapshot_id": "",
        "bcc": "",
        "referer": "",
        "dlp_file": "",
        "destination_app": "",
        "true_obj_type": "",
        "file_lang": "",
        "url": "",
        "true_obj_category": "",
        "cc": "",
        "owner_pdl": "",
        "classification": "",
        "object_type": "",
        "ext_labels": [],
        "exposure": "",
        "dlp_parent_id": 0,
        "owner": "",
        "user_id": ""
    }
    Get Incident Forensics

    API Endpoint: https://<tenant-url>/api/v2/incidents/dlpincidents/{id}/forensics

    Method: GET

    Request Headers

    KeyValue
    Netskope-API-Token<netskope_api_v2_token>
    User-Agentnetskope-ce-6.1.0

    Request Parameters

    KeyValue
    dlp_incident_id in path paramdlp_incident_id

    Sample API Response

    {
    "status": "success",
    "data": {
    "meta": "{\"metadata_content\":\"filename: sensitive_data_onedrive_share.txt file_md5: 0bcafac7ce40ad3ebad1664307a046f1 file_type: text/plain file_lang: ENGLISH object_id: {\\\"drive_id\\\": \\\"b!PM0toX-2uEqSwuqUx0SzyDAe0n7GMw1Eok5wsoIE5ALI55tDhn-rSJB-vB4UWs5e\\\", \\\"driveitem_id\\\": \\\"014GLSS7Z2KV57XD3LXNFLWFO3HXHVREJB\\\", \\\"site_collection_id\\\": \\\"a12dcd3c-b67f-4ab8-92c2-ea94c744b3c8\\\"} ns_text_classifier: others \",\"dlp_match_info\":[{\"dlp_profile_name\":\"DLP-PCI\",\"dlp_rules\":[{\"dlp_rule_name\":\"Bank-CC\",\"dlp_rule_severity\":\"Low\",\"dlp_incident_rule_count\":3,\"dlp_data_identifiers\":[[{\"start_offset\":41,\"score\":1,\"end_offset\":56,\"entity_name\":\"industries/banking/bank_names/us\",\"type\":\"content\",\"prefix\":\"Number\\n\\n\\n\\n\",\"match\":\"American Express\",\"suffix\":\"\\n\\n\"},{\"start_offset\":59,\"score\":1,\"end_offset\":73,\"entity_name\":\"numbers/payment_card_numbers/major\",\"type\":\"content\",\"match\":\"378282XXXXX0005\",\"suffix\":\"\\n\\n\\n\\nAmerican\"}],[{\"start_offset\":78,\"score\":1,\"end_offset\":93,\"entity_name\":\"industries/banking/bank_names/us\",\"type\":\"content\",\"prefix\":\"378282XXXXX0005\\n\\n\\n\\n\",\"match\":\"American Express\",\"suffix\":\"\\n\\n\"},{\"start_offset\":96,\"score\":1,\"end_offset\":110,\"entity_name\":\"numbers/payment_card_numbers/major\",\"type\":\"content\",\"match\":\"371449XXXXX8431\",\"suffix\":\"\\n\\n\\n\\nAmerican\"}],[{\"start_offset\":115,\"score\":1,\"end_offset\":130,\"entity_name\":\"industries/banking/bank_names/us\",\"type\":\"content\",\"prefix\":\"371449XXXXX8431\\n\\n\\n\\n\",\"match\":\"American Express\",\"suffix\":\" Corporate\"},{\"start_offset\":143,\"score\":1,\"end_offset\":157,\"entity_name\":\"numbers/payment_card_numbers/major\",\"type\":\"content\",\"prefix\":\"\\n\\n\",\"match\":\"378734XXXXX1000\",\"suffix\":\"\\n\\n\\n\\nAustralian\"}]]}],\"dlp_action\":\"quarantine\",\"action_threshold_met\":true,\"dlp_policy\":\"CDS Data Protection Policy\",\"dlp_scan_type\":\"Ongoing\",\"dlp_policy_hash\":\"policy hash\"},{\"dlp_profile_name\":\"US Financial Data\",\"dlp_rules\":[{\"dlp_rule_name\":\"US-Bank-CC\",\"dlp_rule_severity\":\"Low\",\"dlp_incident_rule_count\":2,\"dlp_data_identifiers\":[[{\"start_offset\":19,\"score\":1,\"end_offset\":29,\"entity_name\":\"numbers/payment_card_number_terms/eng\",\"type\":\"content\",\"prefix\":\"Type\\n\\n\",\"match\":\"Credit Card\",\"suffix\":\" Number\"},{\"start_offset\":41,\"score\":1,\"end_offset\":56,\"entity_name\":\"industries/banking/bank_names/us\",\"type\":\"content\",\"prefix\":\"\\n\\n\\n\\n\",\"match\":\"American Express\",\"suffix\":\"\\n\\n\"},{\"start_offset\":59,\"score\":1,\"end_offset\":73,\"entity_name\":\"numbers/payment_card_numbers/major\",\"type\":\"content\",\"match\":\"378282XXXXX0005\",\"suffix\":\"\\n\\n\\n\\nAmerican\"}],[{\"start_offset\":115,\"score\":1,\"end_offset\":130,\"entity_name\":\"industries/banking/bank_names/us\",\"type\":\"content\",\"prefix\":\"3714XXXXXXXX31\\n\\n\\n\\n\",\"match\":\"American Express\",\"suffix\":\" Corporate\"},{\"start_offset\":143,\"score\":1,\"end_offset\":157,\"entity_name\":\"numbers/payment_card_numbers/major\",\"type\":\"content\",\"prefix\":\"\\n\\n\",\"match\":\"378734XXXXX1000\",\"suffix\":\"\\n\\n\\n\\nAustralian\"},{\"start_offset\":203,\"score\":1,\"end_offset\":213,\"entity_name\":\"numbers/payment_card_number_terms/eng\",\"type\":\"content\",\"prefix\":\"...5610591081018250\\n\\n\\n\\n\",\"match\":\"Diners Club\",\"suffix\":\"\\n\\n30569309025904\"}]]}],\"dlp_action\":\"quarantine\",\"action_threshold_met\":true,\"dlp_policy\":\"CDS Data Protection Policy\",\"dlp_scan_type\":\"Ongoing\",\"dlp_policy_hash\":\"policy hash\"}]}",
    "content": " Credit Card Type\n\nCredit Card Number\n\n\n\nAmerican Express\n\n37XXXXXXXXX0005\n\n\n\nAmerican Express\n\n37XXXXXXXXX8431\n\n\n\nAmerican Express Corporate\n\n37XXXXXXXXX1000\n\n\n\nAustralian BankCard\n\n5610XXXXXXXX50\n\n\n\nDiners Club\n\n30569XXXXXXXX5904\n\n\n\nDiners Club\n\n3852XXXXXXXX37\n\n\n\nDiscover\n\n60111XXXXXXXX117\n\n\n\nDiscover\n\n6011XXXXXXXX424\n\n\n\nJCB\n\n35301XXXXXXXX00\n\n\n\nJCB\n\n356XXXXXXXX05\n\n\n\nMasterCard\n\n555XXXXXXXX444\n\n\n\nMasterCard\n\n5105XXXXXXXX00\n\n\n\nVisa\n\n41XXXXXXXX111\n\n\n\nVisa\n\n401XXXXXXXX1881\n\n\n\nVisa\n\n422XXXXXXXX222"
    }
    }
    Get Endpoint Events

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/events/endpoint
    Method: GET
    Request Headers

    KeyValue
    Netskope-API-Token<netskope_api_v2_token>
    User-Agentnetskope-ce-6.1.0

    Sample API Response

    {
        "_id": "dffd23ac520f696e1c4bd020",
        "access_method": "Endpoint",
        "activity_type": "Process Start",
        "alert": "no",
        "alert_generated": false,
        "computer_name": "win11-50-1-92",
        "device_type": "Bluetooth File Transfer",
        "os": "Windows",
        "os_details": "Microsoft Windows 11 Pro 10.0.22621 64-bit",
        "policy_action": "allow",
        "process_name": "python.exe",
        "process_path": "\\??\\C:\\Program Files\\Python312\\python.exe",
        "sub_type": "SUBTYPE_DEVICE_CONTROL",
        "timestamp": 1725847324,
        "type": "endpoint",
        "user": "shubham.singhal@crestdata.ai",
        "record_type": "epdlp",
        "executable_hash": "",
        "location": "",
        "device_sn": "",
        "app": "",
        "destination_file_name": "",
        "printer_identifier": "",
        "file_type": "",
        "dlp_profile_name": "",
        "dlp_profile": "",
        "event_recovered": false,
        "destination_file_path": "",
        "dlp_incident_id": 0,
        "device_name": "",
        "source_file_directory": "",
        "alert_type": "",
        "process_cert_subject": "",
        "policy_name": "",
        "source_file_name": "",
        "incident_id": 0,
        "action": "",
        "policy_name_enforced": "",
        "policy_version": "",
        "executable_signed": false,
        "file_size": 0,
        "justification": "",
        "product_id": "",
        "vendor_id": "",
        "device_id": "",
        "destination_file_directory": "",
        "dlp_rule": "",
        "device": "",
        "alert_name": "",
        "pid": "",
        "port": "",
        "connection_type": "",
        "sha256": "",
        "policy_action_enforced": "",
        "activity": "",
        "driver": "",
        "unc_path": "",
        "file_origin": "",
        "os_user_name": "",
        "md5": ""
    }
    Create a Client Status Iterator

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/iterator/netskope_ce_cs_iterator?
    Method: POST
    Request Headers

    KeyValue
    User-Agentnetskope-ce-6.1.0
    AuthorizationBearer <v2 token>

    Request Parameters

    KeyValue
    eventtypeclientstatus

    Sample API Response – if created successfully [202]

    {
    "message":"Creation of the iterator, netskope_ce_cs_<unique_id_added> is in progress. Please use the iterator status API to check the status of the iterator. Please note that the iterator name has changed by appending an identifier to ensure uniqueness."
    }

    Sample API Response – if iterator cannot be created as already exists [400]

    {
    "message":"Only one iterator is allowed per event type. Please use the existing iterator,<iterator_name>, or delete the existing iterator."
    }
    Check Status of a Client

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/iterator/<iterator_name>
    Method: GET
    Request Headers

    KeyValue
    User-Agentnetskope-ce-6.1.0
    AuthorizationBearer <v2 token>

    Sample API Response

    {
    "status": "Ready"
    }
    Fetch data from a Client Status Iterator

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/iterator/<iterator_name>/events
    Method: GET
    Request Headers

    KeyValue
    User-Agentnetskope-ce-6.1.0
    AuthorizationBearer <v2 token>

    Request Parameters

    KeyValue
    operationnext

    Sample API Response

    _id,as,asn,city,client_install_time,client_version,count,continent,country,device_hash,device_id,enriched,guid,heart_beat,host_info.client_version,host_info.device_make,host_info.device_model,host_info.hostname,host_info.last_update_timestamp,host_info.mac_addresses,host_info.managementID,host_info.nsdeviceuid,host_info.old_nsdeviceuid,host_info.os,host_info.os_version,host_info.serial_number,host_info.steering_config,isp,last_connected_from_private_ip,last_connected_from_public_ip,last_event_timestamp,last_seen_device_event.actor,last_seen_device_event.event,last_seen_device_event.event_details,last_seen_device_event.npa_status,last_seen_device_event.service_name,last_seen_device_event.status,last_seen_device_event.status_v2,last_seen_device_event.timestamp,latitude,longitude,organization,postal_code,region,timestamp,user_info.device_classification_status,user_info.orgkey,user_info.userkey,user_info.username,zipcode,record_type
    a7b8a3dd4aa3bebfac869f21,,,,0,123.0.0.2272,1,,,84a3c71061af4152f4e961f9,0AGE55ntv6Lg06dd2F30_092BDAE2-138E-38A4-1BC3-6BC72C4663E8,false,a9981877-c2be-4d8f-bf31-27410d8269d8,false,,"VMware, Inc.","VMware7,1",Win11-50-1-105,1740377213,00:50:56:81:A7:00,,092BDAE2-138E-38A4-1BC3-6BC72C4663E8,AFADEEE3-C9F6-3C54-E215-46EE64F4358C,0,11.0.22621,VMware-42 01 fa 68 fb 6b 7c 57-20 3c 42 df d2 c7 02 32,Default tenant config,,0.0.0.0,,1741034210,0,17,,8,Internet Security,0,0,1741034210,0,0,,,,0,0,lDFAMb4aR2ohwCHthoV,0AGE55ntv6Lg06dd2F30,nilay.modi@crestdata.ai,"396321",clientstatus
    1c07aa9d8ad899d02b7c083b,,,,0,123.0.0.2272,1,,,84a3c71061af4152f4e961f9,0AGE55ntv6Lg06dd2F30_092BDAE2-138E-38A4-1BC3-6BC72C4663E8,false,a9981877-c2be-4d8f-bf31-27410d8269d8,false,,"VMware, Inc.","VMware7,1",Win11-50-1-105,1740377213,00:50:56:81:A7:00,,092BDAE2-138E-38A4-1BC3-6BC72C4663E8,AFADEEE3-C9F6-3C54-E215-46EE64F4358C,0,11.0.22621,VMware-42 01 fa 68 fb 6b 7c 57-20 3c 42 df d2 c7 02 32,Default tenant config,,0.0.0.0,,1741034205,0,7,Tunnel Down Due to SSL Error,8,Internet Security,1,0,1741034205,0,0,,,,0,0,lDFAMb4aR2ohwCHthoV,0AGE55ntv6Lg06dd2F30,nilay.modi@crestdata.ai,"396321",clientstatus

    Sample API Response Headers

    Delete a Client Status Iterator

    API Endpoint: https://<tenant-url>/api/v2/events/dataexport/iterator/netskope_ce_cs_iterator_28b7611b-da34-4836-8bdb-89caa3320b6e
    Method: GET
    Request Headers

    KeyValue
    User-Agentnetskope-ce-6.1.0
    AuthorizationBearer <v2 token>

    Sample API Response

    {
    "message": "Successfully deleted the iterator, netskope_ce_cs_iterator_28b7611b-da34-4836-8bdb-89caa3320b6e."
    }

    Note:

    For more details of the iterator, refer to the documentation.

    User Agent

    netskope-ce-6.1.0

    Workflow

    1. Generate a v1 token, and/or (preferably) a v2 RBACv3 token for your Netskope tenant.
    2. Configure the Netskope Tenant plugin.
    3. Validate the plugin.

    Watch a Video

    Click play to watch a video.

     

    Generate a V1 Token

    Using a v1 token is not recommended. If required, follow these steps:

    1. In your Netskope tenant, go to Settings > Tools > REST API v1.
    1. Click Generate New Token.
    1. Click Generate.
    1. Click the edit icon located directly beneath the token to adjust the token’s expiration.
      By default, the token is generated with no expiry. Choose the expiry duration from the dropdown menu. Select from 30 days, 60 days, 90 days, 180 days, or 365 days.
    1. Click Save.
    1. Copy the token. It will be required when configuring the Netskope Tenant Plugin in Cloud Exchange.

    Generate a V2 (RBACv3) Token

    1. In your Netskope tenant, go to Settings > Administration > Administrators & Roles.
    1. Click Service Account.
    2. Enter a Service Account Name.
    3. Select a Role for the Service Account.

      Note

      For Cloud Exchange, a predefined role called Netskope Cloud Exchange exists in the Netskope Tenant. This role has all the required permissions to use Cloud Exchange.

    1. Enter an Expire time. Select from Day(s), Hour(s), Week(s), Year(s).
    1. Click Save and copy the token. It is required when configuring the Netskope Tenant Plugin in Cloud Exchange.

    Configure the Netskope Tenant Plugin

    1. In Cloud Exchange, go to Settings > Plugin Store.

    2. Search for and select the Netskope Tenant v1.6.1 plugin.

    3. Enter a tenant plugin name, tenant URL, and a V1 API token or V2 API token.

      Make sure to enter the full tenant URL (like https://example.de.goskope.com).

      To generate an API token, you can refer to the Generate a V2 (RBACv3) Token section.

      V1 API token is only needed when sharing Hashes to Netskope.
    4. Click Save

    Troubleshooting the Netskope Plugin

    Receiving an Error while Configuring the Tenant

    Getting the error: The Netskope tenant API v2 token does not have necessary permissions configured. Refer to the list of endpoints for which the token is missing permission. **

    Cause: The provided v2 token does not have the minimum required permissions to configure the tenant plugin in Cloud Exchange.

    What to do:

    1. Go to Logging and look for a warning log similar to the following pattern:
      “TENANT Netskope Tenant (Required) [Netskope Tenant]: For **, received 403 error for following endpoint(s)”
    2. Expand the log and get the list of endpoints for which permissions are missing.
    1. Now update the v2 token permissions and add the permission for the shown endpoint.
    Receiving a Connection Error. Check the tenant URL and network settings.

    Cause: This error might be occurring either due to an invalid tenant URL, or due to a network connectivity issue of the machine.

    What to do:

    1. Validate that the tenant URL starts with https://, and it should be the full tenant URL (like https://example.goskope.com)
    2. If the tenant URL is correct, validate Cloud Exchange tenant is able to communicate with your Netskope tenant URL.
    3. Rerun the setup script and enter proxy details if required, and the full tenant URL, then check to see if the tenant connectivity check is passed. If the connectivity check is failed, reach out to your IT team.
    Receiving an API Token Expired Banner in Cloud Exchange

    After configuring Netskope Tenant, you’re seeing The Netskope tenant API token has expired for <tenant_name> error. Generate a new token, or re-issue the token, and then update the tenant configuration to resume communication between a Netskope Tenant and Cloud Exchange.

    Cause: This banner is visible due to the V2 token or the RBAC V3 token that you are using is either expired, revoked, or reissued from the tenant.

    What to do:

    1. If you are using a V2 token, go to your tenant and check if the V2 token is expired or not. If it is expired, you can change the expiration time. And you can also reissue the token and use it to edit the tenant configuration from Settings > Netskope Tenants.
    2. If you are using a RBAC V3 token, same as a V2 token, you can change the expiration time of the token (no need to update in the plugin in this case, as it will be directly be reflected in the existing added token in the config since it was not reissue/revoked). If the token was revoked/reissued, use the new token in the tenant configuration.
    3. After updating the token, the banner will be removed after a successful sync of the plugin.
    4. If the token expired banner appears and the token is not expired, edit the tenant and save without making any changes.
    Pulled Alert/Event Count Mismatch from Netskope Tenant for a Specific Time Range During Historical Data Pull

    If the count of alerts/events pulled from the Netskope tenant differs from the number available on the tenant for a specific time range during a historical pull, it may be due to that during the historical data pull, the plugin uses timestamp_hwm as the pagination marker. In some cases, events were not processed when the timestamp_hwm value exceeded the requested end_time returned in the Netskope API response. This behavior occasionally resulted in a mismatch between the alert/event counts on the tenant and those pulled into CLS.

    What to do:

    Update the Netskope Tenant plugin to v1.6.0 in Cloud Exchange v6.0.0 or above.

    Receiving Error while Configuring Multiple Plugins

    Getting the error: Error: Value error, Error while creating iterator with name netskope_ce_cs_iterator_**. Cannot create Client Status Iterator. One iterator already exists for the Client Status event for your tenant. Delete the existing iterator to continue.

    Cause: Due to API Limitations of Client Status iterator, creation of more than one iterator is not possible.

    What to do:

    1. Users can delete the already existing iterator using API, and create a new one from the plugin.
    2. If a user removes the Client Status event type from one plugin or deletes the Tenant plugin with an iterator, it will automatically delete the iterator from Netskope Tenant. And by configuring a new plugin, users can create an iterator.

    For more details on iterator deletion, refer to the documentation and reach out to your Netskope tenant support to delete an iterator.

    Known Behaviors

    • While upgrading the tenant plugin, if the user chooses to use the ‘skip’ button then CE will not skip upgrading or will not disable the tenant plugin.
    • It is recommended to use Netskope Log Shipper v2.3.1 and Netskope Risk Exchange v1.8.0 with Netskope Tenant v1.6.1 
    • It is recommended to configure 1 Tenant plugin per Netskope Tenant. If you are using multiple tenant plugins for the same Netskope tenant then you may encounter errors related to the Client Status iterator while using the Netskope Log Shipper plugin or Netskope Risk Exchange plugin.
    • It is not recommended to use multiple Netskope Tenant plugins with the same Netskope Tenant. If you have configured Netskope Log Shipper or Netskope Risk Exchange plugin with the Netskope Tenant and you delete the client status iterator then both the plugins will throw error for deleting the Client Status Iterator and you will not be able to use the Netskope Log Shipper or Netskope Risk Exchange plugin.
      TENANT Netskope Tenant (Required) [crest-plugin-support]: Error occurred while Deleting Client Status Iterator netskope_ce_cs_iterator_1aef2620-80bc-43b2-ac1d-31d652ee0xxx for tenant https://crest-plugin-support.de.goskope.com. 
    In this Topic
    • Netskope Tenant Plugin