Source

Netskope

Collect, transform, and route cloud security Events and Alerts

Collect threat intelligence Events and Alerts from Netskope’s SSE (Security Service Edge) and SASE (Secure Access Service Edge) products. Shape them and route them to downstream monitoring/dashboard services or storage.

How Does It Work

This integration is facilitated through Cribl Stream’s REST/API Collector.

  • In Netskope, generate an API token with appropriate scopes.

  • In Cribl Stream, configure a Collector via Sources>Collectors>REST.

  • Set Discover type to Item List, and enter the Discover items, you want to pull.

  • Set the Collect URL to your tenant, followed by the base API call you are making, with ${id} at the end.

  • Set the method to GET.

  • Set the Collect parameters to operation, `head`.

  • Set the appropriate Collect headers.

  • Save, test, and schedule your Collector.

  • Cribl Stream will start receiving data from the Netskope endpoint as it becomes available.

Docs

Cribl, the Data Engine for IT and Security, empowers organizations to transform their data strategy. Customers use Cribl’s suite of products to collect, process, route, and analyze all IT and security data, delivering the flexibility, choice, and control required to adapt to their ever-changing needs.

We offer free training, certifications, and a free tier across our products. Our community Slack features Cribl engineers, partners, and customers who can answer your questions as you get started and continue to build and evolve. We also offer a variety of hands-on-Sandboxes for those interested in how companies globally leverage our products for their data challenges.