Collect threat intelligence Events and Alerts from Netskope’s SSE (Security Service Edge) and SASE (Secure Access Service Edge) products. Shape them and route them to downstream monitoring/dashboard services or storage.
How Does It Work
This integration is facilitated through Cribl Stream’s REST/API Collector.
In Netskope, generate an API token with appropriate scopes.
In Cribl Stream, configure a Collector via Sources>Collectors>REST.
Set Discover type to Item List, and enter the Discover items, you want to pull.
Set the Collect URL to your tenant, followed by the base API call you are making, with ${id} at the end.
Set the method to GET.
Set the Collect parameters to operation, `head`.
Set the appropriate Collect headers.
Save, test, and schedule your Collector.
Cribl Stream will start receiving data from the Netskope endpoint as it becomes available.