netskope_api_v2
Netskope API v2 provides a powerful interface for managing and monitoring Netskope deployments. It enables users to retrieve alerts and events, manage URL lists, and control clients. With Netskope API v2, organizations can proactively respond to security threats, enforce web access policies, and efficiently administer their Netskope environment.
Network Security · Netskope
Details
| ID | netskope_api_v2 |
|---|---|
| Provider | Netskope |
| Category | Network Security |
| From Version | 6.9.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Supported Modules | Agentix XSIAM |
README
Netskope API v2 provides a powerful interface for managing and monitoring Netskope deployments. It enables users to retrieve alerts and events, manage URL lists, and control clients. With Netskope API v2, organizations can proactively respond to security threats, enforce web access policies, and efficiently administer their Netskope environment.
This integration was integrated and tested with version 2 of the Netskope API.
To successfully instantiate an instance of the Netskope API v2 integration under the RBACv3 framework, follow the steps below.
Note: Netskope has deprecated the legacy single-step API token generation process. All new and migrated tenants must use RBACv3 to create API tokens through Service Accounts.
Step 1: Create a Service Account (RBACv3)
Follow the instructions under the section Create a New Service Account.
Step 2: Assign required functional roles
Ensure the Service Account has access to the following functional areas:
In total 4 sections need to be enabled:
- Administration
- Access Control
- DLP
- Events & Analytics

For Administration
In the Administration section, select Function > Audit Log and grant it View rights.

Under Users & Groups, select Manage:

Events & Analytics
Functions that need to be set to view: Application Events, Page Events, Network Events, and Alerts.

For Access Control
Select Access Control, for the Infrastructure function, grant View rights.

For the URL List, set to Manage and Apply.

For DLP
For DLP Incident, set to View.

Step 3
- API Token: Copy the generated API token and store it securely.
- Server URL: Construct the server URL using your account name and region. Example:
If your account name isxsoarand the region isde, your Server URL is: https://xsoar.de.goskope.com/
Configue Netskope (API v2) in Cortex
| Parameter | Description | Required |
|---|---|---|
| Server URL | True | |
| Use system proxy settings | False | |
| Trust any certificate (not secure) | False | |
| API token | Netskope API access token (make sure to generate token for the required endpoints). | True |
| First fetch timestamp | First alert created date to fetch. e.g., “1 min ago”,”2 weeks ago”,”3 months ago”. | False |
| Maximum incidents per fetch | Maximum number of incidents per fetch. Default is 50. The maximum is 100. | False |
| Maximum Netskope events per fetch. Max value is 200. | False | |
| Maximum Netskope DLP incidents per fetch. Max value is 200. | False | |
| Fetch Events | Fetch events as incidents, in addition to the alerts. | False |
| Fetch DLP incidents | Fetch Netskope DLP incidents as incidents, in addition to the alerts. | False |
| Event types to fetch. | The event types to fetch as incidents. | False |
| Alerts Query | Free text query to filter the fetched alerts. For more information, visit Netskope documentation (https://docs.netskope.com/en/get-alerts-data.html). | False |
| Events Query | Free text query to filter the fetched events (if configured). For more information, visit Netskope documentation (https://docs.netskope.com/en/get-alerts-data.html). | False |
| Incident type | False | |
| Fetch incidents | False | |
| User Email | The user email for update incident in Netskope. | False |
| Incidents Fetch Interval | False | |
| Incident Mirroring Direction | Cortex XSOAR only parameter. | False |
| Close Mirrored XSOAR Incident | Cortex XSOAR only parameter. | False |
| Close Mirrored Netskope Incident | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears with the command details in the War Room.
netskope-alert-list
Retrieve alerts generated by Netskope. Select the desired alerts using the alert_type parameter. Mandatory inputs include start_time and end_time, or insertion_start_time and insertion_end_time (If end_time or insertion_end_time is not provided, it defaults to the current date and time). Additionally, it is not permissible to supply a combination of the aforementioned options.
Base Command
netskope-alert-list
Input
| Argument Name | Description | Required |
|---|---|---|
| start_time | Restrict events to those that have dates greater than the provided date string (for example “YYYY-MM-DDThh:mm”, “1 min ago”, “2 weeks ago”). When this argument is provided, the ‘end_time’ argument must be provided as well. | Optional |
| end_time | Restrict events to those that have dates less than or equal to the provided date string (for example “YYYY-MM-DDThh:mm”, “1 min ago”, “2 weeks ago”). When this argument is provided, the ‘start_time’ argument must also be provided. If the start_time argument is provided and this argument is not - the default value will be set for now. | Optional |
| insertion_start_time | Restrict events to those that were inserted into the system after the provided date string (for example “YYYY-MM-DDThh:mm”, “1 min ago”, “2 weeks ago”). When this argument is provided, the ‘insertion_end_time’ argument must also be provided. | Optional |
| insertion_end_time | Restrict events to those that were inserted into the system before the provided date string (for example “YYYY-MM-DDThh:mm”, “1 min ago”, “2 weeks ago”). When this argument is provided, the ‘insertion_start_time’ argument must also be provided. If the insertion_start_time argument is provided and this argument is not - the default value will be set for now. | Optional |
| query | Free query to filter the alerts. For example, “alert_name like test”. For more information, please visit Netskope documentation: https://docs.netskope.com/en/get-alerts-data.html. | Optional |
| alert_type | Select alerts by their type. | Optional |
| acked | Whether to retrieve acknowledged alerts. Possible values are: True, False. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Netskope.Alert._appsession_start | String | The timestamp marking the start of an application session. |
| Netskope.Alert._category_id | String | The unique identifier for a category. |
| Netskope.Alert._category_name | String | The name or label associated with a category. |
| Netskope.Alert._category_tags | Number | Numeric tags or labels associated with the category. |
| Netskope.Alert._content_version | Number | A numeric value representing the content version. |
| Netskope.Alert._correlation_id | String | An identifier used for correlating events or data. |
| Netskope.Alert._creation_timestamp | Number | The timestamp when the data or event was created. |
| Netskope.Alert._ef_received_at | Date | The timestamp indicating when the event was received. |
| Netskope.Alert._event_id | String | A unique identifier for the event. |
| Netskope.Alert._forwarded_by | String | Information indicating the source responsible for forwarding the event. |
| Netskope.Alert._gef_src_dp | String | The source data path for the event. |
| Netskope.Alert._id | String | A unique identifier for the event or data. |
| Netskope.Alert._insertion_epoch_timestamp | Number | Insertion timestamp. |
| Netskope.Alert._nshostname | String | The hostname associated with Netskope. |
| Netskope.Alert._raw_event_inserted_at | Date | The timestamp indicating when the raw event was inserted. |
| Netskope.Alert._service_identifier | String | An identifier associated with a specific service. |
| Netskope.Alert._session_begin | String | The timestamp marking the beginning of a session. |
| Netskope.Alert._skip_geoip_lookup | String | A flag indicating whether GeoIP lookup should be skipped. |
| Netskope.Alert._src_epoch_now | Number | A numeric value representing the source epoch. |
| Netskope.Alert.access_method | String | Cloud app traffic can be steered to the Netskope cloud using different deployment methods such as Client (Netskope Client), Secure Forwarder etc. Administrators can also upload firewall and/or proxy logs for log analytics. This field shows the actual access method that triggered the event. For log uploads this shows the actual log type such as PAN, Websense, etc. |
| Netskope.Alert.acked | String | Whether the user acknowledged the alert or not. |
| Netskope.Alert.action | String | Action taken on the event for the policy. |
| Netskope.Alert.activity | String | Description of the user-performed activity. |
| Netskope.Alert.alert | String | Indicates whether the alert is generated or not. Populated as yes for all alerts. |
| Netskope.Alert.alert_name | String | Name of the alert. |
| Netskope.Alert.alert_type | String | Type of the alert. |
| Netskope.Alert.app | String | Specific cloud application used by the user (e.g., app = Dropbox). |
| Netskope.Alert.app_session_id | Number | Unique App/Site Session ID for traffic_type = CloudApp and Web. An app session starts when a user starts using a cloud app/site and ends once they have been inactive for a certain period of time (15 mins). Use app_session_id to check all the user activities in a single app session. app_session_id is unique for a user, device, browser, and domain. |
| Netskope.Alert.appcategory | String | Application category as designated by Netskope. |
| Netskope.Alert.appsuite | String | Information related to the suite of applications or software used. |
| Netskope.Alert.browser | String | Shows the actual browser from where the cloud app was accessed. |
| Netskope.Alert.browser_session_id | Number | Browser session ID. If there is an idle timeout of 15 minutes, it will time out the session. |
| Netskope.Alert.category | String | A classification or grouping label for data or events. |
| Netskope.Alert.cci | Number | Cloud Confidence Index, indicating the readiness and security of cloud applications. |
| Netskope.Alert.ccl | String | “Cloud Confidence Level. CCL measures the enterprise readiness of the cloud apps taking into consideration those apps’ security, auditability, and business continuity. Each app is assigned one of five cloud confidence levels: excellent, high, medium, low, or poor. Useful for querying if users are accessing a cloud app with a lower CCL.” |
| Netskope.Alert.connection_id | Number | Each connection has a unique ID. Shows the ID for the connection event. |
| Netskope.Alert.count | Number | Number of raw log lines/events sessionized or suppressed during the suppressed interval. |
| Netskope.Alert.device | String | Device type from where the user accessed the cloud app. It could be a Macintosh, Windows device, iPad, etc. |
| Netskope.Alert.device_classification | String | Designation of the device as determined by the Netskope Client as to whether the device is managed or not. |
| Netskope.Alert.domain | String | Domain value. This will hold the host header value or SNI or extracted from an absolute URI. |
| Netskope.Alert.dst_country | String | Application’s two-letter country code as determined by Maxmind or IP2Location Geolocation database. |
| Netskope.Alert.dst_latitude | Number | Latitude of the application as determined by Maxmind or IP2Location Geolocation database. |
| Netskope.Alert.dst_location | String | Application’s city as determined by maxmind or IP2Location Geolocation database. |
| Netskope.Alert.dst_longitude | Number | Longitude of the application as determined by Maxmind or IP2Location Geolocation database. |
| Netskope.Alert.dst_region | String | Application’s state or region as determined by Maxmind or IP2Location Geolocation database. |
| Netskope.Alert.dst_timezone | String | Destination timezone. |
| Netskope.Alert.dst_zipcode | String | Application’s zip code as determined by Maxmind or IP2Location Geolocation database. |
| Netskope.Alert.dstip | String | IP address where the destination app is hosted. |
| Netskope.Alert.hostname | String | Host name. |
| Netskope.Alert.incident_id | Number | A unique identifier for an incident or event. |
| Netskope.Alert.ja3 | String | A field indicating JA3 information. |
| Netskope.Alert.ja3s | String | A field indicating JA3S information. |
| Netskope.Alert.managed_app | String | Whether or not the app in question is managed. |
| Netskope.Alert.managementID | String | Management ID. |
| Netskope.Alert.netskope_pop | String | Netskope Point of Presence, related to network infrastructure. |
| Netskope.Alert.notify_template | String | The template used for notifications or alerts. |
| Netskope.Alert.nsdeviceuid | String | Device identifiers on macOS and Windows. |
| Netskope.Alert.organization_unit | String | Organization units for which the event correlates to. This ties to user information extracted from Active Directory using the Directory Importer/AD Connector application. |
| Netskope.Alert.os | String | Operating system of the host that generated the event. |
| Netskope.Alert.os_version | String | Operating system version of the host. |
| Netskope.Alert.other_categories | String | Additional categories or labels not specified elsewhere. |
| Netskope.Alert.page | String | The URL of the originating page. |
| Netskope.Alert.page_site | String | Information about the web page or site being accessed. |
| Netskope.Alert.policy | String | Name of the policy configured by an admin. |
| Netskope.Alert.policy_id | String | The Netskope internal ID for the policy created by an admin. |
| Netskope.Alert.port | String | The network port used for communication. |
| Netskope.Alert.protocol | String | The communication protocol or method used. |
| Netskope.Alert.request_id | Number | Unique request ID for the event. |
| Netskope.Alert.severity | String | Severity used by watchlist and malware alerts. |
| Netskope.Alert.site | String | For traffic_type = CloudApp, site = app, and for traffic_type = Web, it will be the second-level domain name + top-level domain name. For example, in “www.cnn.com”, it is “cnn.com”. |
| Netskope.Alert.src_country | String | User’s country’s two-letter country code as determined by Maxmind or IP2Location Geolocation database. |
| Netskope.Alert.src_latitude | Number | Latitude of the user as determined by Maxmind or IP2Location Geolocation database. |
| Netskope.Alert.src_location | String | User’s city as determined by Maxmind or IP2Location Geolocation database. |
| Netskope.Alert.src_longitude | Number | Longitude of the user as determined by Maxmind or IP2Location Geolocation database. |
| Netskope.Alert.src_region | String | Source state or region as determined by Maxmind or IP2Location Geolocation database. |
| Netskope.Alert.src_time | Date | A timestamp associated with the source or event. |
| Netskope.Alert.src_timezone | String | Source timezone. Shows the long-format timezone designation. |
| Netskope.Alert.src_zipcode | String | Source zip code as determined by Maxmind or IP2Location Geolocation database. |
| Netskope.Alert.srcip | String | IP address of the source/user. |
| Netskope.Alert.telemetry_app | String | Typically, SaaS app websites use web analytics code within the pages to gather analytic data. When a SaaS app action or page is shown, there is subsequent traffic generated to tracking apps such as doubleclick.net, Optimizely, etc. These tracking apps are listed if applicable in the Telemetry App field. |
| Netskope.Alert.timestamp | Number | Timestamp when the event/alert happened. Event timestamp in Unix epoch format. |
| Netskope.Alert.traffic_type | String | “Type of the traffic: CloudApp or Web. CloudApp indicates CASB and web indicates HTTP traffic. Web traffic is only captured for inline access method. It is currently not captured for Risk Insights.” |
| Netskope.Alert.transaction_id | Number | Unique ID for a given request/response. |
| Netskope.Alert.type | String | Shows if it is an application event or a connection event. Application events are recorded to track user events inside a cloud app. Connection events show the actual HTTP connection. |
| Netskope.Alert.ur_normalized | String | All lowercase user email. |
| Netskope.Alert.url | String | URL of the application that the user visited as provided by the log or data plane traffic. |
| Netskope.Alert.user | String | User email. |
| Netskope.Alert.useragent | String | Browser HTTP user agent header. |
| Netskope.Alert.userip | String | IP address of the user. |
| Netskope.Alert.userkey | String | User ID or email. |
| Netskope.Alert._client_timeout | Number | Information related to client timeouts. |
| Netskope.Alert._dlp_backup_profile | String | Information related to DLP (Data Loss Prevention) backup profiles. |
| Netskope.Alert._nsp_dur_back | Number | Duration information for NSP (Network Security Platform) on the back end. |
| Netskope.Alert._nsp_dur_front | Number | Duration information for NSP on the front end. |
| Netskope.Alert._nsp_retrans_back | Number | Retransmission information for NSP on the back end. |
| Netskope.Alert._nsp_retrans_front | Number | Retransmission information for NSP on the front end. |
| Netskope.Alert._nsp_rtt_back | Number | Round-trip time information for NSP on the back end. |
| Netskope.Alert._nsp_rtt_front | Number | Round-trip time information for NSP on the front end. |
| Netskope.Alert._resource_name | String | The name associated with a resource. |
| Netskope.Alert._scan_source | String | Information indicating the source of a scan. |
| Netskope.Alert._tenant_max_file_size | Number | The maximum file size allowed for a tenant. |
| Netskope.Alert.all_policy_matches | String | Information related to policy matches. |
| Netskope.Alert.browser_version | String | Browser version. |
| Netskope.Alert.file_size | Number | Size of the file in bytes. |
| Netskope.Alert.file_type | String | File type. |
| Netskope.Alert.md5 | String | MD5 of the file. |
| Netskope.Alert.object | String | Name of the object which is being acted on. It could be a filename, folder name, report name, document name, etc. |
| Netskope.Alert.object_type | String | Type of the object which is being acted on. Object type could be a file, folder, report, document, message, etc. |
| Netskope.Alert.web_universal_connector | String | Universal web connector information. |
Command example
!netskope-alert-list start_time="2023-05-05 11:06" alert_type=policy limit=2
Context Example
{
"Netskope": {
"Alert": [
{
"_appsession_start": "yes",
"_category_id": "8",
"_category_name": "Collaboration",
"_category_tags": [10001, 564, 8],
"_content_version": 1687272302,
"_correlation_id": "011c0f84-9938-460b-8cbe-dab38fa6cb31",
"_creation_timestamp": 1687656279,
"_ef_received_at": 1687656276462,
"_event_id": "724d1174-d78c-4197-8243-4fbd3644b192",
"_forwarded_by": "msg-relayer",
"_gef_src_dp": "IL-TLV1",
"_id": "c3c98336e9d6807dd821b8dc",
"_insertion_epoch_timestamp": 1687656283,
"_nshostname": "dppool1-2-egress",
"_raw_event_inserted_at": 1687656276776,
"_service_identifier": "service-nsproxy",
"_session_begin": "1",
"_skip_geoip_lookup": "yes",
"_src_epoch_now": 1687667040,
"access_method": "Client",
"acked": "false",
"action": "block",
"activity": "Browse",
"alert": "yes",
"alert_id": "c3c98336e9d6807dd821b8dc",
"alert_name": "365 block",
"alert_type": "policy",
"app": "Microsoft Teams",
"app_session_id": 3379014715943843300,
"appcategory": "Collaboration",
"appsuite": "Office365",
"browser": "Native",
"browser_session_id": 2893692091617575400,
"category": "Collaboration",
"cci": 92,
"ccl": "excellent",
"connection_id": 1717056737521399300,
"count": 1,
"device": "Windows Device",
"device_classification": "unmanaged",
"domain": "config.teams.microsoft.com",
"dst_country": "US",
"dst_latitude": 47.682899475097656,
"dst_location": "Redmond",
"dst_longitude": -122.12090301513672,
"dst_region": "Washington",
"dst_timezone": "America/Los_Angeles",
"dst_zipcode": "N/A",
"dstip": "8.8.8.8",
"hostname": "DESKTOP-TOR2VO7",
"incident_id": 6782360912641091000,
"ja3": "a0e9f5d64349fb13191bc781f81f42e1",
"ja3s": "NotAvailable",
"managed_app": "no",
"managementID": "",
"netskope_pop": "IL-TLV1",
"notify_template": "block_page.html",
"nsdeviceuid": "A633E874-D3B2-0FB7-F5CC-AF89F428B182",
"organization_unit": "",
"os": "Windows 10",
"os_version": "Windows 10",
"other_categories": ["Test web Policy Beni", "Technology", "Collaboration"],
"page": "config.teams.microsoft.com",
"page_site": "Microsoft Teams",
"policy": "365 block",
"policy_id": "84BE7DC6087E38BCA19B3788C5E02A67 2023-06-22 14:42:51.404368",
"port": "443",
"protocol": "HTTPS/1.1",
"request_id": 2605870162901070000,
"severity": "unknown",
"site": "Microsoft Teams",
"src_country": "IL",
"src_latitude": 32.0803,
"src_location": "Tel Aviv",
"src_longitude": 34.7805,
"src_region": "Tel Aviv",
"src_time": "Sun Jun 25 04:24:00 2023",
"src_timezone": "Asia/Jerusalem",
"src_zipcode": "N/A",
"srcip": "8.8.8.8",
"telemetry_app": "",
"timestamp": "2023-06-25T01:24:36.000Z",
"traffic_type": "CloudApp",
"transaction_id": 6782360912641091000,
"type": "nspolicy",
"ur_normalized": "example@qmasters.co",
"url": "config.teams.microsoft.com/config/v1/ODSP_Sync_Client/23.119.0606.0001",
"user": "example@qmasters.co",
"useragent": "OneDrive-23.119.0606.0001",
"userip": "8.8.8.8",
"userkey": "example@qmasters.co"
},
{
"_appsession_start": "yes",
"_category_id": "8",
"_category_name": "Collaboration",
"_category_tags": [10001, 564, 8],
"_content_version": 1687272302,
"_correlation_id": "46647142-2f24-4802-b8f5-22814e80353a",
"_creation_timestamp": 1687659879,
"_ef_received_at": 1687659876494,
"_event_id": "6827a5eb-de85-48af-8eae-6d3034084fd6",
"_forwarded_by": "msg-relayer",
"_gef_src_dp": "IL-TLV1",
"_id": "da711d311019f02d79ebc8f4",
"_insertion_epoch_timestamp": 1687659883,
"_nshostname": "dppool1-2-egress",
"_raw_event_inserted_at": 1687659876771,
"_service_identifier": "service-nsproxy",
"_session_begin": "1",
"_skip_geoip_lookup": "yes",
"_src_epoch_now": 1687670640,
"access_method": "Client",
"acked": "false",
"action": "block",
"activity": "Browse",
"alert": "yes",
"alert_id": "da711d311019f02d79ebc8f4",
"alert_name": "365 block",
"alert_type": "policy",
"app": "Microsoft Teams",
"app_session_id": 4359394467077842400,
"appcategory": "Collaboration",
"appsuite": "Office365",
"browser": "Native",
"browser_session_id": 2893692091617575400,
"category": "Collaboration",
"cci": 92,
"ccl": "excellent",
"connection_id": 8981978357397935000,
"count": 1,
"device": "Windows Device",
"device_classification": "unmanaged",
"domain": "config.teams.microsoft.com",
"dst_country": "AT",
"dst_latitude": 48.2049,
"dst_location": "Vienna",
"dst_longitude": 16.3662,
"dst_region": "Vienna",
"dst_timezone": "Europe/Vienna",
"dst_zipcode": "1010",
"dstip": "8.8.8.8",
"hostname": "DESKTOP-TOR2VO7",
"incident_id": 1478029261577663500,
"ja3": "a0e9f5d64349fb13191bc781f81f42e1",
"ja3s": "NotAvailable",
"managed_app": "no",
"managementID": "",
"netskope_pop": "IL-TLV1",
"notify_template": "block_page.html",
"nsdeviceuid": "A633E874-D3B2-0FB7-F5CC-AF89F428B182",
"organization_unit": "",
"os": "Windows 10",
"os_version": "Windows 10",
"other_categories": ["Test web Policy Beni", "Technology", "Collaboration"],
"page": "config.teams.microsoft.com",
"page_site": "Microsoft Teams",
"policy": "365 block",
"policy_id": "84BE7DC6087E38BCA19B3788C5E02A67 2023-06-22 14:42:51.404368",
"port": "443",
"protocol": "HTTPS/1.1",
"request_id": 2605900362175087600,
"severity": "unknown",
"site": "Microsoft Teams",
"src_country": "IL",
"src_latitude": 32.0803,
"src_location": "Tel Aviv",
"src_longitude": 34.7805,
"src_region": "Tel Aviv",
"src_time": "Sun Jun 25 05:24:00 2023",
"src_timezone": "Asia/Jerusalem",
"src_zipcode": "N/A",
"srcip": "8.8.8.8",
"telemetry_app": "",
"timestamp": "2023-06-25T02:24:36.000Z",
"traffic_type": "CloudApp",
"transaction_id": 1478029261577663500,
"type": "nspolicy",
"ur_normalized": "example@qmasters.co",
"url": "config.teams.microsoft.com/config/v1/ODSP_Sync_Client/23.119.0606.0001",
"user": "example@qmasters.co",
"useragent": "OneDrive-23.119.0606.0001",
"userip": "8.8.8.8",
"userkey": "example@qmasters.co"
}
]
}
}
Human Readable Output
Alert List
Showing page 1.
Current page size: 2.
Alert Id Alert Name Alert Type Severity Action Activity Type Category Name Event Id Domain Dst Country Policy Port Protocol Md5 Timestamp c3c98336e9d6807dd821b8dc 365 block policy unknown block Browse nspolicy Collaboration 724d1174-d78c-4197-8243-4fbd3644b192 config.teams.microsoft.com US 365 block 443 HTTPS/1.1 2023-06-25T01:24:36.000Z da711d311019f02d79ebc8f4 365 block policy unknown block Browse nspolicy Collaboration 6827a5eb-de85-48af-8eae-6d3034084fd6 config.teams.microsoft.com AT 365 block 443 HTTPS/1.1 2023-06-25T02:24:36.000Z
netskope-event-list
Get events extracted from SaaS traffic. You may choose what events to receive with the event_type parameter. You must provide start_time and end_time, or insertion_start_time and insertion_end_time (If end_time or insertion_end_time isn’t provided - it defaults to the current date and time). Also, you cannot provide a combination of the options mentioned above.
Base Command
netskope-event-list
Input
| Argument Name | Description | Required |
|---|---|---|
| event_type | Select events by their type. Available types: page,application,audit,infrastructure,network. Possible values are: page, application, audit, infrastructure, network. | Required |
| query | Free query to filter the events. For example, “app eq Dropbox”. For more information, please visit Netskope documentation: https://docs.netskope.com/en/get-events-data.html. | Optional |
| start_time | Restrict events to those that have dates greater than the provided date string (for example “YYYY-MM-DDThh:mm”, “1 min ago”, “2 weeks ago”). When this argument is provided, the ‘end_time’ argument must also be provided. | Optional |
| end_time | Restrict events to those that have dates less than or equal to the provided date string (for example “YYYY-MM-DDThh:mm”, “1 min ago”, “2 weeks ago”). When this argument is provided, the ‘start_time’ argument must also be provided. If the start_time argument is provided and this argument is not - the default value will be set for now. | Optional |
| insertion_start_time | Restrict events to those that were inserted into the system after the provided date string (for example “YYYY-MM-DDThh:mm”, “1 min ago”, “2 weeks ago”). When this argument is provided, the ‘insertion_end_time’ argument must also be provided. | Optional |
| insertion_end_time | Restrict events to those that were inserted into the system before the provided date string (for example “YYYY-MM-DDThh:mm”, “1 min ago”, “2 weeks ago”). When this argument is provided, the ‘insertion_start_time’ argument must also be provided. If the insertion_start_time argument is provided and this argument is not - the default value will be set for now. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Netskope.Event._appsession_start | String | Netskope event application session start. |
| Netskope.Event._category_id | String | Netskope event category ID. |
| Netskope.Event._category_name | String | Netskope event category name. |
| Netskope.Event._category_tags | Number | Netskope event category tags. |
| Netskope.Event._content_version | Number | Netskope event content version. |
| Netskope.Event._correlation_id | String | Netskope event correlation ID. |
| Netskope.Event._creation_timestamp | Number | Netskope event creation timestamp. |
| Netskope.Event._ef_received_at | Date | The timestamp indicating when the event was received. |
| Netskope.Event._event_id | String | Netskope event event ID. |
| Netskope.Event._forwarded_by | String | Netskope event forwarded by. |
| Netskope.Event._gef_src_dp | String | The source data path for the event. |
| Netskope.Event._id | String | Netskope event ID. |
| Netskope.Event._insertion_epoch_timestamp | Number | Netskope event insertion epoch timestamp |
| Netskope.Event._nshostname | String | The hostname associated with Netskope. |
| Netskope.Event._raw_event_inserted_at | Date | The date the Netskope raw event was inserted. |
| Netskope.Event._service_identifier | String | Netskope event service identifier. |
| Netskope.Event._session_begin | String | The timestamp marking the beginning of a session. |
| Netskope.Event._skip_geoip_lookup | String | Netskope event skip GeoIP lookup. |
| Netskope.Event._src_epoch_now | Number | A numeric value representing the source epoch. |
| Netskope.Event.access_method | String | Netskope event access method. |
| Netskope.Event.action | String | Netskope event action. |
| Netskope.Event.activity | String | Netskope event activity. |
| Netskope.Event.alert | String | Netskope event alert. |
| Netskope.Event.app | String | Netskope event app. |
| Netskope.Event.app_session_id | Number | Netskope event app session ID. |
| Netskope.Event.appcategory | String | Netskope event app category. |
| Netskope.Event.appsuite | String | Netskope event app suite. |
| Netskope.Event.browser | String | Netskope event browser. |
| Netskope.Event.browser_session_id | Number | Netskope event browser session ID. |
| Netskope.Event.category | String | Netskope event category. |
| Netskope.Event.cci | Number | Netskope event Cloud Confidence Index. |
| Netskope.Event.ccl | String | Netskope event Cloud Confidence Levels. |
| Netskope.Event.connection_id | Number | Netskope event connection ID. |
| Netskope.Event.count | Number | Netskope event count. |
| Netskope.Event.device | String | Netskope event device. |
| Netskope.Event.device_classification | String | Netskope event device classification. |
| Netskope.Event.dom | String | Netskope event Document Object Model (DOM). |
| Netskope.Event.dst_country | String | Netskope event destination country. |
| Netskope.Event.dst_latitude | Number | Netskope event destination latitude. |
| Netskope.Event.dst_location | String | Netskope event destination location. |
| Netskope.Event.dst_longitude | Number | Netskope event destination longitude. |
| Netskope.Event.dst_region | String | Netskope event destination region. |
| Netskope.Event.dst_timezone | String | Netskope event destination timezone. |
| Netskope.Event.dst_zipcode | String | Netskope event destination zip code. |
| Netskope.Event.dstip | String | Netskope event destination IP. |
| Netskope.Event.hostname | String | Netskope event host name. |
| Netskope.Event.incident_id | Number | Netskope event incident ID. |
| Netskope.Event.ja3 | String | A field indicating JA3 information. |
| Netskope.Event.ja3s | String | A field indicating JA3S information. |
| Netskope.Event.managed_app | String | Netskope event managed app. |
| Netskope.Event.managementID | String | Netskope event management ID. |
| Netskope.Event.netskope_pop | String | Netskope event Netskope POP. |
| Netskope.Event.notify_template | String | Netskope event notify template. |
| Netskope.Event.nsdeviceuid | String | Netskope event Netskope device UID. |
| Netskope.Event.organization_unit | String | Netskope event organization unit. |
| Netskope.Event.os | String | Netskope event operating system. |
| Netskope.Event.os_version | String | Netskope event operating system version. |
| Netskope.Event.other_categories | String | Netskope event other categories. |
| Netskope.Event.page | String | Netskope event page. |
| Netskope.Event.page_site | String | Netskope event page site. |
| Netskope.Event.policy | String | Netskope event policy. |
| Netskope.Event.policy_id | String | Netskope event policy ID. |
| Netskope.Event.port | Number | Netskope event port. |
| Netskope.Event.protocol | String | Netskope event protocol. |
| Netskope.Event.request_id | Number | Netskope event request ID. |
| Netskope.Event.severity | String | Netskope event severity. |
| Netskope.Event.site | String | Netskope event site. |
| Netskope.Event.src_country | String | Netskope event source country. |
| Netskope.Event.src_latitude | Number | Netskope event source latitude. |
| Netskope.Event.src_location | String | Netskope event source location. |
| Netskope.Event.src_longitude | Number | Netskope event source longitude. |
| Netskope.Event.src_region | String | Netskope event source region. |
| Netskope.Event.src_time | Date | Netskope event source time. |
| Netskope.Event.src_timezone | String | Netskope event source timezone. |
| Netskope.Event.src_zipcode | String | Netskope event source zip code. |
| Netskope.Event.srcip | String | Netskope event source IP. |
| Netskope.Event.telemetry_app | String | Netskope event telemetry app. |
| Netskope.Event.timestamp | Number | Netskope event timestamp. |
| Netskope.Event.traffic_type | String | Netskope event traffic type. |
| Netskope.Event.transaction_id | Number | Netskope event transaction ID. |
| Netskope.Event.type | String | Netskope event type. |
| Netskope.Event.ur_normalized | String | All lowercase user email. |
| Netskope.Event.url | String | Netskope event URL. |
| Netskope.Event.user | String | Netskope event user. |
| Netskope.Event.useragent | String | Netskope event user agent. |
| Netskope.Event.userip | String | Netskope event user IP. |
| Netskope.Event.userkey | String | Netskope event user key. |
Command example
!netskope-event-list event_type=page start_time="10 days ago" limit=2
Human Readable Output
Event List
Showing page 1.
Current page size: 2.
No entries.
netskope-url-list-update
Update the URL List with the values provided. please note that this command overrides the list.
Base Command
netskope-url-list-update
Input
| Argument Name | Description | Required |
|---|---|---|
| url_list_id | The URL list ID to update (use netskope-url-list-list command to get URL list ID). | Required |
| name | The updated URL list name. | Required |
| urls | The updated URL list items (For Exact - Enter URLs like .example.com, or IP addresses, separated by a new line. For Regex - Enter URLs like ^client[0-9]\.google\.com , ^app\.slack\.com/./netskope, or ^google.com, separated by a new line). | Required |
| list_type | The updated URL list type. Possible values are: exact, regex. | Required |
| deploy | Whether to deploy URL list changes or not. Default is False. Possible values are: True, False. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Netskope.URLList.id | Number | Netskope URL list ID. |
| Netskope.URLList.name | String | Netskope URL list name. |
| Netskope.URLList.data.urls | String | Netskope URL list data URLs. |
| Netskope.URLList.data.type | String | Netskope URL list data type. |
| Netskope.URLList.data.json_version | Number | Netskope URL list data JSON version. |
| Netskope.URLList.modify_by | String | Netskope URL list modify by. |
| Netskope.URLList.modify_time | Date | Netskope URL list modify time. |
| Netskope.URLList.modify_type | String | Netskope URL list modify type. |
| Netskope.URLList.pending | String | Netskope URL list pending status. |
Command example
!netskope-url-list-update url_list_id=11 name="QMASTERS list" urls="google.com" list_type=regex deploy=false
Context Example
{
"Netskope": {
"URLList": {
"id": 11,
"json_version": 2,
"modify_by": "Tal New Token",
"modify_time": "2023-07-18",
"modify_type": "Edited",
"name": "QMASTERS list",
"pending": "pending",
"type": "regex",
"urls": ["google.com"]
}
}
}
Human Readable Output
URL List
Id Json Version Modify By Modify Time Modify Type Name Pending Type Urls 11 2 Tal New Token 2023-07-18 Edited QMASTERS list pending regex google.com
netskope-url-list-create
Create a new URL list.
Base Command
netskope-url-list-create
Input
| Argument Name | Description | Required |
|---|---|---|
| name | The unique name for the URL list. | Required |
| urls | The URL list items (For Exact - Enter URLs like .example.com, or IP addresses, separated by a new line. For Regex - Enter URLs like ^client[0-9]\.google\.com , ^app\.slack\.com/./netskope, or ^google.com, separated by a new line). | Required |
| list_type | The URL list type. Possible values are: exact, regex. | Required |
| deploy | Whether to deploy URL list changes or not. Default is False. Possible values are: True, False. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Netskope.URLList.id | Number | Netskope URL list ID. |
| Netskope.URLList.name | String | Netskope URL list name. |
| Netskope.URLList.data.urls | String | Netskope URL list data URLs. |
| Netskope.URLList.data.type | String | Netskope URL list data type. |
| Netskope.URLList.data.json_version | Number | Netskope URL list data JSON version. |
| Netskope.URLList.modify_type | String | Netskope URL list modify type. |
| Netskope.URLList.modify_by | String | Netskope URL list modify by. |
| Netskope.URLList.modify_time | Date | Netskope URL list modify time. |
| Netskope.URLList.pending | String | Netskope URL list pending status. |
Command example
!netskope-url-list-create name="New QMASTERS list" urls="xsoar.com,qmasters.com,google.com" list_type=regex deploy=false
Context Example
{
"Netskope": {
"URLList": {
"id": 12,
"json_version": 2,
"modify_by": "Tal New Token",
"modify_time": "2023-07-18",
"modify_type": "Created",
"name": "New QMASTERS list",
"pending": "pending",
"type": "regex",
"urls": ["xsoar.com", "qmasters.com", "google.com"]
}
}
}
Human Readable Output
URL List
Id Json Version Modify By Modify Time Modify Type Name Pending Type Urls 12 2 Tal New Token 2023-07-18 Created New QMASTERS list pending regex xsoar.com,
qmasters.com,
google.com
netskope-url-lists-list
Get all URL Lists or a specific by specifying the list ID.
Base Command
netskope-url-lists-list
Input
| Argument Name | Description | Required |
|---|---|---|
| url_list_id | The URL list ID to get. | Optional |
| pending | Get a list of only applied or pending URL lists. Possible values are: applied, pending. | Optional |
| field | Comma separated data values to return in response call (for example: name, id, data, modify_by, modify_time, modify_type, pending). Defaults to all values. | Optional |
| all_results | Whether to retrieve all results or not. Defaults is false. Possible values are: True, False. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Netskope.URLList.id | Number | Netskope URL list ID. |
| Netskope.URLList.name | String | Netskope URL list name. |
| Netskope.URLList.data.urls | String | Netskope URL list data URLs. |
| Netskope.URLList.modify_by | String | Netskope URL list modify by. |
| Netskope.URLList.modify_time | Date | Netskope URL list modify time. |
| Netskope.URLList.modify_type | String | Netskope URL list modify type. |
| Netskope.URLList.pending | String | Netskope URL list pending status. |
Command example
!netskope-url-lists-list
Context Example
{
"Netskope": {
"URLList": [
{
"data": {
"json_version": 2,
"type": "exact",
"urls": ["g.g"]
},
"id": 1,
"modify_by": "example@qmasters.co",
"modify_time": "2023-07-16T00:00:00.000Z",
"modify_type": "Edited",
"name": "myList",
"pending": 0
},
{
"data": {
"json_version": 2,
"type": "regex",
"urls": ["google.com"]
},
"id": 2,
"modify_by": "Tal New Token",
"modify_time": "2023-07-18T00:00:00.000Z",
"modify_type": "Edited",
"name": "NewURLList",
"pending": 0
},
{
"data": {
"json_version": 2,
"type": "exact",
"urls": ["google.com", "www.abc.com", "example.com", "lulu.com"]
},
"id": 4,
"modify_by": "Netskope REST API",
"modify_time": "2023-07-05T10:24:57.000Z",
"modify_type": "Edited",
"name": "Tal-newURLlist",
"pending": 0
},
{
"data": {
"json_version": 2,
"type": "exact",
"urls": ["google.com", "example.com", "lulu.com"]
},
"id": 5,
"modify_by": "Netskope REST API",
"modify_time": "2023-07-05T00:00:00.000Z",
"modify_type": "Created",
"name": "New URL list",
"pending": 0
},
{
"data": {
"json_version": 2,
"type": "exact",
"urls": ["google.com", "example.com", "lulu.com"]
},
"id": 6,
"modify_by": "Netskope REST API",
"modify_time": "2023-07-05T00:00:00.000Z",
"modify_type": "Created",
"name": "New URL list 2",
"pending": 0
},
{
"data": {
"json_version": 2,
"type": "regex",
"urls": ["xsoar.com", "qmasters.com"]
},
"id": 8,
"modify_by": "Netskope REST API",
"modify_time": "2023-07-17T00:00:00.000Z",
"modify_type": "Created",
"name": "NewNewURLlist",
"pending": 0
},
{
"data": {
"json_version": 2,
"type": "regex",
"urls": ["xsoar.com", "qmasters.com"]
},
"id": 9,
"modify_by": "Netskope REST API",
"modify_time": "2023-07-17T00:00:00.000Z",
"modify_type": "Created",
"name": "NewNewURLlist1",
"pending": 0
}
]
}
}
Human Readable Output
URL List
Id Json Version Modify By Modify Time Modify Type Name Pending Type Urls 1 2 example@qmasters.co 2023-07-16T00:00:00.000Z Edited myList applied exact g.g 2 2 Tal New Token 2023-07-18T00:00:00.000Z Edited NewURLList applied regex google.com 4 2 Netskope REST API 2023-07-05T10:24:57.000Z Edited Tal-newURLlist applied exact google.com,
www.abc.com,
example.com,
lulu.com5 2 Netskope REST API 2023-07-05T00:00:00.000Z Created New URL list applied exact google.com,
example.com,
lulu.com6 2 Netskope REST API 2023-07-05T00:00:00.000Z Created New URL list 2 applied exact google.com,
example.com,
lulu.com8 2 Netskope REST API 2023-07-17T00:00:00.000Z Created NewNewURLlist applied regex xsoar.com,
qmasters.com9 2 Netskope REST API 2023-07-17T00:00:00.000Z Created NewNewURLlist1 applied regex xsoar.com,
qmasters.com
netskope-url-list-delete
Delete a URL list by the list ID.
Base Command
netskope-url-list-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| url_list_id | The URL list ID to delete (use netskope-url-list-list to get the URL list ID). | Required |
| deploy | Whether to deploy URL list changes or not. Default is False. Possible values are: True, False. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Netskope.URLList.id | Number | Netskope URL list ID. |
| Netskope.URLList.name | String | Netskope URL list name. |
Command example
!netskope-url-list-delete url_list_id=10
Context Example
{
"Netskope": {
"URLList": {
"data": {
"json_version": 2,
"type": "regex",
"urls": ["xsoar.com", "qmasters.com"]
},
"id": 10,
"modify_by": "Netskope REST API",
"modify_time": "2023-07-17T00:00:00.000Z",
"modify_type": "Deleted",
"name": "TalURLlist",
"pending": 1
}
}
}
Human Readable Output
The URL list 10 was deleted successfully
netskope-client-list
Get information about Netskope SCIM users. The command provides a list of users who have been imported into the Netskope tenant through SCIM integration. Users imported through other methods, such as manual CSV import or manual creation, will not be included in the returned results.
Base Command
netskope-client-list
Input
| Argument Name | Description | Required |
|---|---|---|
| filter | Filter the Netskope user by ‘key eq value’ template. For example: userName eq “someUserName” OR externalId eq “User-Ext_id”. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Netskope.Client.id | Number | Netskope client ID. |
| Netskope.Client.name | String | Netskope client name. |
| Netskope.Client.userName | String | Netskope client username. |
| Netskope.Client.externalId | String | Netskope client external ID. |
| Netskope.Client.active | Boolean | Netskope client activate. |
| Netskope.Client.emails | String | Netskope client emails. |
Command example
!netskope-client-list page=1 limit=2
Context Example
{
"Netskope": {
"Client": [
{
"active": true,
"client_id": "6a4dbb07-f465-4a6c-8af2-1c84ced65010",
"emails": ["email1@netskope.local"],
"family_name": "last_name",
"given_name": "first_name",
"user_name": "upn1"
},
{
"active": true,
"client_id": "f8d26597-e4a4-400d-a24b-40318a9e80e5",
"emails": ["email11@netskope.local"],
"family_name": "last_name1",
"given_name": "first_name1",
"user_name": "upn2"
}
]
}
}
Human Readable Output
Client List
Showing page 1.
Current page size: 2.
Client Id User Name Given Name Family Name Emails Active 6a4dbb07-f465-4a6c-8af2-1c84ced65010 upn1 first_name last_name email1@netskope.local true f8d26597-e4a4-400d-a24b-40318a9e80e5 upn2 first_name1 last_name1 email11@netskope.local true
netskope-url-list-add
Update the URL list with the values provided. Note that this command appends the list.
Base Command
netskope-url-list-add
Input
| Argument Name | Description | Required |
|---|---|---|
| url_list_id | The URL list ID to update (use netskope-url-list-list command to get URL list ID). | Required |
| urls | The updated URL list items (For Exact - Enter URLs like .example.com, or IP addresses, separated by a new line. For Regex - Enter URLs like ^client[0-9]\.google\.com , ^app\.slack\.com/./netskope, or ^google.com, separated by a new line). | Required |
| list_type | The updated URL list type. Possible values are: exact, regex. | Required |
| deploy | Whether to deploy URL list changes or not. Possible values are: True, False. Default is false. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Netskope.URLList.id | Number | Netskope URL list ID. |
| Netskope.URLList.name | String | Netskope URL list name. |
| Netskope.URLList.data.urls | String | Netskope URL list data URLs. |
| Netskope.URLList.data.type | String | Netskope URL list data type. |
| Netskope.URLList.data.json_version | Number | Netskope URL list data JSON version. |
| Netskope.URLList.modify_by | String | Netskope URL list modify by. |
| Netskope.URLList.modify_time | Date | Netskope URL list modify time. |
| Netskope.URLList.modify_type | String | Netskope URL list modify type. |
| Netskope.URLList.pending | Number | Netskope URL list pending. |
netskope-incident-dlp-list
Fetch DLP incidents.
Base Command
netskope-incident-dlp-list
Input
| Argument Name | Description | Required |
|---|---|---|
| start_time | Restrict incidents to those that have updated dates greater than the provided date string (for example “YYYY-MM-DDThh:mm”, “1 min ago”, “2 weeks ago”). Default is ‘1 hour ago’. Default is 1 hour ago. | Optional |
| end_time | Restrict incidents to those that have updated dates less than or equal to the provided date string (for example “YYYY-MM-DDThh:mm”, “1 min ago”, “2 weeks ago”). Default is ‘now’. Default is now. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Netskope.Incident._id | String | |
| Netskope.Incident.access_method | String | |
| Netskope.Incident.acting_user | String | |
| Netskope.Incident.activity | String | |
| Netskope.Incident.app | String | |
| Netskope.Incident.app_session_id | Number | |
| Netskope.Incident.assignee | String | |
| Netskope.Incident.connection_id | Number | |
| Netskope.Incident.dlp_incident_id | Number | |
| Netskope.Incident.dlp_match_info | Unknown | |
| Netskope.Incident.dlp_match_info.dlp_action | String | |
| Netskope.Incident.dlp_match_info.dlp_forensic_id | Number | |
| Netskope.Incident.dlp_match_info.dlp_policy | String | |
| Netskope.Incident.dlp_match_info.dlp_profile_name | String | |
| Netskope.Incident.dlp_match_info.dlp_rules | Unknown | |
| Netskope.Incident.dlp_match_info.dlp_rules.dlp_incident_rule_count | Number | |
| Netskope.Incident.dlp_match_info.dlp_rules.dlp_match_type | String | |
| Netskope.Incident.dlp_match_info.dlp_rules.dlp_rule_name | String | |
| Netskope.Incident.dlp_match_info.dlp_rules.dlp_rule_severity | String | |
| Netskope.Incident.dlp_parent_id | Number | |
| Netskope.Incident.dst_location | String | |
| Netskope.Incident.file_lang | String | |
| Netskope.Incident.file_size | Number | |
| Netskope.Incident.file_type | String | |
| Netskope.Incident.from_user | String | |
| Netskope.Incident.instance_id | String | |
| Netskope.Incident.md5 | String | |
| Netskope.Incident.object | String | |
| Netskope.Incident.object_id | String | |
| Netskope.Incident.object_type | String | |
| Netskope.Incident.severity | String | |
| Netskope.Incident.site | String | |
| Netskope.Incident.src_location | String | |
| Netskope.Incident.status | String | |
| Netskope.Incident.timestamp | Number | |
| Netskope.Incident.title | String | |
| Netskope.Incident.true_obj_category | String | |
| Netskope.Incident.true_obj_type | String | |
| Netskope.Incident.url | String | |
| Netskope.Incident.user | String | |
| Netskope.Incident.owner_pdl | String | |
| Netskope.Incident.classification | String | |
| Netskope.Incident.to_user | String | |
| Netskope.Incident.cc | String | |
| Netskope.Incident.owner | String | |
| Netskope.Incident.destination_site | String | |
| Netskope.Incident.user_id | String | |
| Netskope.Incident.instance | String | |
| Netskope.Incident.channel | String | |
| Netskope.Incident.bcc | String | |
| Netskope.Incident.inline_dlp_match_info | Unknown | |
| Netskope.Incident.exposure | String | |
| Netskope.Incident.file_path | String | |
| Netskope.Incident.original_file_snapshot_id | String | |
| Netskope.Incident.destination_app | String | |
| Netskope.Incident.latest_incident_id | Number | |
| Netskope.Incident.dlp_file | String | |
| Netskope.Incident.zip_file_id | String | |
| Netskope.Incident.referer | String | |
| Netskope.Incident.destination_instance_id | String |
Command example
!netskope-incident-dlp-list
Context Example
{
"Netskope": {
"Incident": [
{
"_id": "dg",
"access_method": "Client",
"acting_user": "d@d.co",
"activity": "Upload",
"app": "Microsoft Office 365 OneDrive for Business",
"app_session_id": 6089117609268013425,
"assignee": "d@d.co",
"connection_id": 1888383367374049276,
"dlp_incident_id": 7061311227778495851,
"dlp_match_info": [
{
"dlp_action": "block",
"dlp_forensic_id": 7061311227778495851,
"dlp_policy": "DLP test policy - Beni",
"dlp_profile_name": "test dlp profile -beni",
"dlp_rules": [
{
"dlp_incident_rule_count": 1,
"dlp_match_type": "FileFilter",
"dlp_rule_name": "test dlp profile - beni",
"dlp_rule_severity": "Medium"
}
]
}
],
"dlp_parent_id": 7061311227778495851,
"dst_location": "Redmond",
"file_lang": "Unknown",
"file_size": 10,
"file_type": "text/plain",
"from_user": "d@d.co",
"instance_id": "d",
"md5": "fsd",
"object": "d.txt",
"object_id": "01",
"object_type": "File",
"severity": "Critical",
"site": "Microsoft Office 365 OneDrive for Business",
"src_location": "Tel Aviv",
"status": "in_progress",
"timestamp": 1710928898,
"title": "d.txt",
"true_obj_category": "Text",
"true_obj_type": "Plain Text file",
"url": "v1.g.f",
"user": "sdf",
"owner_pdl": "",
"classification": "",
"to_user": "",
"cc": "",
"owner": "",
"destination_site": "",
"user_id": "",
"instance": "",
"channel": "",
"bcc": "",
"inline_dlp_match_info": [],
"exposure": "",
"file_path": "",
"original_file_snapshot_id": "",
"destination_app": "",
"latest_incident_id": 0,
"dlp_file": "",
"zip_file_id": "",
"referer": "",
"destination_instance_id": ""
}
]
}
}
Human Readable Output
Client List
Showing page 1.
Current page size: 2.
Object Id Status Severity Activity Assignee Timestamp Acting User App Instance Id Object Type 12 new High FormPost None 1725903291 None Form
get-mapping-fields
Returns the list of fields for an incident type.
Base Command
get-mapping-fields
Input
| Argument Name | Description | Required |
| —————– | ————— | ———— |
Context Output
There is no context output for this command.
update-remote-system
Updates the remote incident or detection with local incident or detection changes. This method is only used for debugging purposes and will not update the current incident or detection.
Base Command
update-remote-system
Input
| Argument Name | Description | Required |
| —————– | ————— | ———— |
Context Output
There is no context output for this command.
get-remote-data
Gets remote data from a remote incident. This method does not update the current incident, and should be used for debugging purposes.
Base Command
get-remote-data
Input
| Argument Name | Description | Required |
|---|---|---|
| id | The ticket ID. | Required |
| lastUpdate | Retrieves entries that were created after lastUpdate. | Required |
Context Output
There is no context output for this command.
get-modified-remote-data
Gets the list of incidents that were modified since the last update time. Note that this method is here for debugging purposes. The get-modified-remote-data command is used as part of a Mirroring feature, which is available in Cortex XSAIM/XSOAR from version 6.1.
Base Command
get-modified-remote-data
Input
| Argument Name | Description | Required |
|---|---|---|
| lastUpdate | A date string in local time representing the last time the incident was updated. The incident is only returned if it was modified after the last update time. | Optional |
Context Output
There is no context output for this command.
Incident Mirroring
You can enable incident mirroring between Cortex XSAIM/XSOAR incidents and Netskope (API v2) LOCAL corresponding events (available from Cortex XSAIM/XSOAR version 6.0.0).
To set up the mirroring:
- Enable Fetching incidents in your instance configuration.
-
In the Mirroring Direction integration parameter, select in which direction the incidents should be mirrored:
Option Description None Turns off incident mirroring. Incoming Any changes in Netskope (API v2) LOCAL events (mirroring incoming fields) will be reflected in Cortex XSOAR incidents. Outgoing Any changes in Cortex XSAIM/XSOAR incidents will be reflected in Netskope (API v2) LOCAL events (outgoing mirrored fields). Incoming and Outgoing - Optional: Check the Close Mirrored XSAIM/XSOAR Incident integration parameter to close the Cortex XSAIM/XSOAR incident when the corresponding event is closed in Netskope (API v2) LOCAL.
Newly fetched incidents will be mirrored in the chosen direction. However, this selection does not affect existing incidents.
Important Note: To ensure the mirroring works as expected, mappers are required, both for incoming and outgoing, to map the expected fields in Cortex XSAIM/XSOAR and Netskope (API v2) LOCAL.
Configuration parameters
url— Server URL (required)proxy— Use system proxy settingsinsecure— Trust any certificate (not secure)credentials— (required)first_fetch— First fetch timestampmax_fetch— Maximum incidents per fetchmax_events_fetch— Maximum Netskope events per fetch. Max value is 200.max_dlp_incidents_fetch— Maximum Netskope DLP incidents per fetch. Max value is 200.fetch_events— Fetch Eventsfetch_dlp_incidents— Fetch DLP incidentsevent_types— Event types to fetch.alerts_query— Alerts Queryevents_query— Events QueryincidentType— Incident typeisFetch— Fetch incidentsuser_email— User EmailincidentFetchInterval— Incidents Fetch Intervalmirror_direction— Incident Mirroring Directionclose_incident— Close Mirrored XSOAR Incidentclose_netskope_incident— Close Mirrored Netskope Incident
Commands (13)
-
get-mapping-fieldsReturns the list of fields for an incident type.
-
get-modified-remote-dataGets the list of incidents that were modified since the last update time. Note that this method is here for debugging purposes. The get-modified-remote-data command is used as part of a Mirroring feature, which is available in Cortex XSOAR from version 6.1.
-
get-remote-dataGets remote data from a remote incident. This method does not update the current incident, and should be used for debugging purposes.
-
netskope-alert-listGet alerts generated by Netskope. You may choose what alerts to receive with the alert_type parameter. You must provide start_time and end_time, or insertion_start_time and insertion_end_time. (Note that if end_time or insertion_end_time aren't provided. the date time would be set as now.) You cannot provide a combination of the options mentioned above.
-
netskope-client-listGet information about Netskope SCIM users. The command provides a list of users who have been imported into the Netskope tenant through SCIM integration. Users imported through other methods, such as manual CSV import or manual creation, will not be included in the returned results.
-
netskope-event-listGet events extracted from SaaS traffic. You may choose what events to receive with the event_type parameter. You must provide start_time and end_time, or insertion_start_time and insertion_end_time. (Note that if end_time or insertion_end_time aren't provided, the date time would be set as now.) You cannot provide a combination of the options mentioned above.
-
netskope-incident-dlp-listFetch DLP incidents by update time. The maximum recommended time range should be no more from 3 days.
-
netskope-url-list-addUpdate the URL list with the values provided. Note that this command appends the list.
-
netskope-url-list-createCreate a new URL list.
-
netskope-url-list-deleteDelete a URL list by the list ID.
-
netskope-url-list-updateUpdate the URL list with the values provided. Note that this command overrides the list.
-
netskope-url-lists-listGet all URL lists or a specific URL list by specifying the list ID.
-
update-remote-systemUpdates the remote incident or detection with local incident or detection changes. This method is only used for debugging purposes and will not update the current incident or detection.
category: Network Security provider: Netskope sectionorder: - Connect - Collect commonfields: id: netskope_api_v2 version: -1 configuration: - defaultvalue: https://{environment}.goskope.com display: Server URL name: url type: 0 required: true section: Connect - defaultvalue: "false" display: Use system proxy settings name: proxy required: false type: 8 section: Connect - defaultvalue: "false" display: Trust any certificate (not secure) name: insecure required: false type: 8 section: Connect - displaypassword: API token name: credentials defaultvalue: "" required: true hiddenusername: true type: 9 section: Connect - additionalinfo: First alert created date to fetch. e.g., "1 min ago","2 weeks ago","3 months ago". defaultvalue: 3 days display: First fetch timestamp name: first_fetch type: 0 required: false section: Collect - additionalinfo: Maximum number of incidents per fetch. Default is 50. The maximum is 100. defaultvalue: "50" display: Maximum incidents per fetch name: max_fetch type: 0 required: false section: Collect - display: Maximum Netskope events per fetch. Max value is 200. name: max_events_fetch defaultvalue: "50" required: false type: 0 section: Collect - display: Maximum Netskope DLP incidents per fetch. Max value is 200. name: max_dlp_incidents_fetch defaultvalue: "50" required: false type: 0 section: Collect - additionalinfo: Fetch events as incidents, in addition to the alerts. display: Fetch Events name: fetch_events required: false type: 8 section: Collect - additionalinfo: Fetch Netskope DLP incidents as incidents, in addition to the alerts. display: Fetch DLP incidents name: fetch_dlp_incidents required: false type: 8 section: Collect - additionalinfo: The event types to fetch as incidents. display: Event types to fetch. name: event_types options: - page - application - audit - infrastructure - network required: false type: 16 section: Collect - additionalinfo: "Free text query to filter the fetched alerts. For more information, visit Netskope documentation (https://docs.netskope.com/en/get-alerts-data.html)." display: Alerts Query name: alerts_query required: false type: 0 section: Collect - additionalinfo: "Free text query to filter the fetched events (if configured). For more information, visit Netskope documentation (https://docs.netskope.com/en/get-alerts-data.html)." display: Events Query name: events_query type: 0 required: false section: Collect - display: Incident type name: incidentType required: false type: 13 section: Collect - display: Fetch incidents name: isFetch type: 8 required: false section: Collect - additionalinfo: The user email for update incident in Netskope. display: User Email name: user_email required: false type: 0 section: Collect - defaultvalue: "1" display: Incidents Fetch Interval name: incidentFetchInterval required: false type: 19 section: Collect - name: mirror_direction display: Incident Mirroring Direction required: false type: 15 defaultvalue: None options: - None - Incoming - Outgoing - Incoming and Outgoing section: Collect hidden: - marketplacev2 - platform additionalinfo: Cortex XSOAR only parameter. - name: close_incident display: Close Mirrored XSOAR Incident required: false type: 8 defaultvalue: "false" section: Collect hidden: - marketplacev2 - platform additionalinfo: Cortex XSOAR only parameter. - name: close_netskope_incident display: Close Mirrored Netskope Incident required: false type: 8 defaultvalue: "false" section: Collect description: Netskope API v2 provides a powerful interface for managing and monitoring Netskope deployments. It enables users to retrieve alerts and events, manage URL lists, and control clients. With Netskope API v2, organizations can proactively respond to security threats, enforce web access policies, and efficiently administer their Netskope environment. display: Netskope (API v2) name: netskope_api_v2 script: commands: - name: netskope-incident-dlp-list description: Fetch DLP incidents by update time. The maximum recommended time range should be no more from 3 days. arguments: - name: start_time description: Restrict incidents to those that have updated dates greater than the provided date string (for example "YYYY-MM-DDThh:mm", "1 min ago", "2 weeks ago"). Default is ‘1 hour ago’. required: false defaultValue: "1 hour ago" - name: end_time description: Restrict incidents to those that have updated dates less than or equal to the provided date string (for example "YYYY-MM-DDThh:mm", "1 min ago", "2 weeks ago"). Default is ‘now’. required: false defaultValue: "now" outputs: - contextPath: Netskope.Incident._id description: Unique identifier for the incident. type: String - contextPath: Netskope.Incident.access_method description: Method used to access the system or service in the incident. type: String - contextPath: Netskope.Incident.acting_user description: User responsible for the action in the incident. type: String - contextPath: Netskope.Incident.activity description: Type of activity that triggered the incident. type: String - contextPath: Netskope.Incident.app description: Application involved in the incident. type: String - contextPath: Netskope.Incident.app_session_id description: Session ID for the application involved in the incident. type: Number - contextPath: Netskope.Incident.assignee description: User assigned to handle the incident. type: String - contextPath: Netskope.Incident.connection_id description: Connection ID related to the incident. type: Number - contextPath: Netskope.Incident.dlp_incident_id description: Data Loss Prevention (DLP) incident ID. type: Number - contextPath: Netskope.Incident.dlp_match_info description: Detailed information about DLP matches related to the incident. type: Unknown - contextPath: Netskope.Incident.dlp_match_info.dlp_action description: DLP action taken in response to the incident. type: String - contextPath: Netskope.Incident.dlp_match_info.dlp_forensic_id description: Forensic ID related to the DLP match. type: Number - contextPath: Netskope.Incident.dlp_match_info.dlp_policy description: DLP policy that triggered the incident. type: String - contextPath: Netskope.Incident.dlp_match_info.dlp_profile_name description: Name of the DLP profile associated with the incident. type: String - contextPath: Netskope.Incident.dlp_match_info.dlp_rules description: Rules associated with the DLP match. type: Unknown - contextPath: Netskope.Incident.dlp_match_info.dlp_rules.dlp_incident_rule_count description: Number of rules triggered in the DLP incident. type: Number - contextPath: Netskope.Incident.dlp_match_info.dlp_rules.dlp_match_type description: Type of DLP match. type: String - contextPath: Netskope.Incident.dlp_match_info.dlp_rules.dlp_rule_name description: Name of the DLP rule triggered. type: String - contextPath: Netskope.Incident.dlp_match_info.dlp_rules.dlp_rule_severity description: Severity of the DLP rule triggered. type: String - contextPath: Netskope.Incident.dlp_parent_id description: Parent ID for related DLP incidents. type: Number - contextPath: Netskope.Incident.dst_location description: Destination location related to the incident. type: String - contextPath: Netskope.Incident.file_lang description: Language of the file involved in the incident. type: String - contextPath: Netskope.Incident.file_size description: Size of the file involved in the incident. type: Number - contextPath: Netskope.Incident.file_type description: Type of file involved in the incident. type: String - contextPath: Netskope.Incident.from_user description: Sender or source user in the incident. type: String - contextPath: Netskope.Incident.instance_id description: Instance ID related to the incident. type: String - contextPath: Netskope.Incident.md5 description: MD5 hash of the file involved in the incident. type: String - contextPath: Netskope.Incident.object description: Object involved in the incident. type: String - contextPath: Netskope.Incident.object_id description: Unique identifier for the object involved in the incident. type: String - contextPath: Netskope.Incident.object_type description: Type of object involved in the incident. type: String - contextPath: Netskope.Incident.severity description: Severity level of the incident. type: String - contextPath: Netskope.Incident.site description: Site associated with the incident. type: String - contextPath: Netskope.Incident.src_location description: Source location related to the incident. type: String - contextPath: Netskope.Incident.status description: Current status of the incident. type: String - contextPath: Netskope.Incident.timestamp description: Timestamp when the incident occurred. type: Number - contextPath: Netskope.Incident.title description: Title or name of the incident. type: String - contextPath: Netskope.Incident.true_obj_category description: Actual category of the object involved in the incident. type: String - contextPath: Netskope.Incident.true_obj_type description: Actual type of the object involved in the incident. type: String - contextPath: Netskope.Incident.url description: URL involved in the incident. type: String - contextPath: Netskope.Incident.user description: User involved in the incident. type: String - contextPath: Netskope.Incident.owner_pdl description: Owner's primary distribution list (PDL). type: String - contextPath: Netskope.Incident.classification description: Classification of the incident. type: String - contextPath: Netskope.Incident.to_user description: Recipient or target user in the incident. type: String - contextPath: Netskope.Incident.cc description: CC'ed users in the incident communication. type: String - contextPath: Netskope.Incident.owner description: Owner of the incident. type: String - contextPath: Netskope.Incident.destination_site description: Destination site associated with the incident. type: String - contextPath: Netskope.Incident.user_id description: Unique identifier for the user involved in the incident. type: String - contextPath: Netskope.Incident.instance description: Instance related to the incident. type: String - contextPath: Netskope.Incident.channel description: Communication channel used in the incident. type: String - contextPath: Netskope.Incident.bcc description: BCC'ed users in the incident communication. type: String - contextPath: Netskope.Incident.inline_dlp_match_info description: Inline DLP match information related to the incident. type: Unknown - contextPath: Netskope.Incident.exposure description: Level of exposure in the incident. type: String - contextPath: Netskope.Incident.file_path description: File path of the file involved in the incident. type: String - contextPath: Netskope.Incident.original_file_snapshot_id description: Original snapshot ID of the file involved in the incident. type: String - contextPath: Netskope.Incident.destination_app description: Destination application involved in the incident. type: String - contextPath: Netskope.Incident.latest_incident_id description: Latest incident ID related to the incident. type: Number - contextPath: Netskope.Incident.dlp_file description: DLP file involved in the incident. type: String - contextPath: Netskope.Incident.zip_file_id description: ID of the ZIP file involved in the incident. type: String - contextPath: Netskope.Incident.referer description: Referer URL involved in the incident. type: String - contextPath: Netskope.Incident.destination_instance_id description: Destination instance ID related to the incident. type: String - arguments: - description: 'Restrict events to those that have dates greater than the provided date string (for example "YYYY-MM-DDThh:mm", "1 min ago", "2 weeks ago"). Note that if this argument is provided, you must also provide the ‘end_time’ argument. ' name: start_time - description: 'Restrict events to those that have dates less than or equal to the provided date string (for example "YYYY-MM-DDThh:mm", "1 min ago", "2 weeks ago"). Note that if this argument is provided, you must also provide the ‘start_time’ argument. If start_time argument is provided and this argument is not - the default value will be set for now.' name: end_time - description: 'Restrict events to those that were inserted to the system after the provided date string (for example "YYYY-MM-DDThh:mm", "1 min ago", "2 weeks ago"). Note that if this argument is provided, you must also provide the ‘insertion_end_time’ argument. ' name: insertion_start_time - description: 'Restrict events to those that were inserted to the system before the provided date string (for example "YYYY-MM-DDThh:mm", "1 min ago", "2 weeks ago"). Note that if this argument is provided, you must also provide the ‘insertion_start_time’ argument. If insertion_start_time argument is provided and this argument is not - the default value will be set for now.' name: insertion_end_time - description: 'Free query by which to filter the alerts. For example, "alert_name like test". For more information, visit Netskope documentation: https://docs.netskope.com/en/get-alerts-data.html.' name: query - auto: PREDEFINED description: Select alerts by their type. name: alert_type predefined: - anomaly - Compromised Credential - policy - Legal Hold - malsite - Malware - DLP - Security Assessment - watchlist - quarantine - Remediation - uba - auto: PREDEFINED description: Whether to retrieve acknowledged alerts or not. name: retrieve_acknowledged predefined: - "True" - "False" - description: "Page number of paginated results. Minimum value: 1." name: page - defaultValue: "50" description: The maximum number of records to retrieve. name: limit description: Get alerts generated by Netskope. You may choose what alerts to receive with the alert_type parameter. You must provide start_time and end_time, or insertion_start_time and insertion_end_time. (Note that if end_time or insertion_end_time aren't provided. the date time would be set as now.) You cannot provide a combination of the options mentioned above. name: netskope-alert-list outputs: - contextPath: Netskope.Alert._appsession_start description: The timestamp marking the start of an application session. type: String - contextPath: Netskope.Alert._category_id description: The unique identifier for a category. type: String - contextPath: Netskope.Alert._category_name description: The name or label associated with a category. type: String - contextPath: Netskope.Alert._category_tags description: Numeric tags or labels associated with the category. type: Number - contextPath: Netskope.Alert._content_version description: A numeric value representing the content version. type: Number - contextPath: Netskope.Alert._correlation_id description: An identifier used for correlating events or data. type: String - contextPath: Netskope.Alert._creation_timestamp description: The timestamp when the data or event was created. type: Number - contextPath: Netskope.Alert._ef_received_at description: The timestamp indicating when the event was received. type: Date - contextPath: Netskope.Alert._event_id description: A unique identifier for the event. type: String - contextPath: Netskope.Alert._forwarded_by description: Information indicating the source responsible for forwarding the event. type: String - contextPath: Netskope.Alert._gef_src_dp description: The source data path for the event. type: String - contextPath: Netskope.Alert._id description: A unique identifier for the event or data. type: String - contextPath: Netskope.Alert._insertion_epoch_timestamp description: Insertion timestamp. type: Number - contextPath: Netskope.Alert._nshostname description: The hostname associated with Netskope. type: String - contextPath: Netskope.Alert._raw_event_inserted_at description: The timestamp indicating when the raw event was inserted. type: Date - contextPath: Netskope.Alert._service_identifier description: An identifier associated with a specific service. type: String - contextPath: Netskope.Alert._session_begin description: The timestamp marking the beginning of a session. type: String - contextPath: Netskope.Alert._skip_geoip_lookup description: A flag indicating whether GeoIP lookup should be skipped. type: String - contextPath: Netskope.Alert._src_epoch_now description: A numeric value representing the source epoch. type: Number - contextPath: Netskope.Alert.access_method description: Cloud app traffic can be steered to the Netskope cloud using different deployment methods such as Client (Netskope Client), Secure Forwarder, etc. Administrators can also upload firewall and/or proxy logs for log analytics. This field shows the actual access method that triggered the event. For log uploads, this shows the actual log type such as PAN, Websense, etc. type: String - contextPath: Netskope.Alert.acked description: Whether the user acknowledged the alert or not. type: String - contextPath: Netskope.Alert.action description: Action taken on the event for the policy. type: String - contextPath: Netskope.Alert.activity description: Description of the user-performed activity. type: String - contextPath: Netskope.Alert.alert description: Indicates whether the alert is generated or not. Populated as yes for all alerts. type: String - contextPath: Netskope.Alert.alert_name description: Name of the alert. type: String - contextPath: Netskope.Alert.alert_type description: Type of the alert. type: String - contextPath: Netskope.Alert.app description: Specific cloud application used by the user (e.g., app = Dropbox). type: String - contextPath: Netskope.Alert.app_session_id description: Unique App/Site Session ID for traffic_type = CloudApp and Web. An app session starts when a user starts using a cloud app/site and ends once they have been inactive for a certain period of time (15 mins). Use app_session_id to check all the user activities in a single app session. app_session_id is unique for a user, device, browser, and domain. type: Number - contextPath: Netskope.Alert.appcategory description: Application category as designated by Netskope. type: String - contextPath: Netskope.Alert.appsuite description: Information related to the suite of applications or software used. type: String - contextPath: Netskope.Alert.browser description: Shows the actual browser from where the cloud app was accessed. type: String - contextPath: Netskope.Alert.browser_session_id description: Browser session ID. If there is an idle timeout of 15 minutes, it will time out the session. type: Number - contextPath: Netskope.Alert.category description: A classification or grouping label for data or events. type: String - contextPath: Netskope.Alert.cci description: Cloud Confidence Index, indicating the readiness and security of cloud applications. type: Number - contextPath: Netskope.Alert.ccl description: "Cloud Confidence Level. CCL measures the enterprise readiness of the cloud apps taking into consideration those apps' security, auditability, and business continuity. Each app is assigned one of five cloud confidence levels: excellent, high, medium, low, or poor. Useful for querying if users are accessing a cloud app with a lower CCL." type: String - contextPath: Netskope.Alert.connection_id description: Each connection has a unique ID. Shows the ID for the connection event. type: Number - contextPath: Netskope.Alert.count description: Number of raw log lines/events sessionized or suppressed during the suppressed interval. type: Number - contextPath: Netskope.Alert.device description: Device type from where the user accessed the cloud app. It could be Macintosh Windows device, iPad, etc. type: String - contextPath: Netskope.Alert.device_classification description: Designation of the device as determined by the Netskope Client as to whether the device is managed or not. type: String - contextPath: Netskope.Alert.domain description: Domain value. This will hold the host header value or SNI or extracted from an absolute URI. type: String - contextPath: Netskope.Alert.dst_country description: Application’s two-letter country code as determined by Maxmind or IP2Location Geodatabase. type: String - contextPath: Netskope.Alert.dst_latitude description: Latitude of the application as determined by MaxMind or IP2Location Geolocation database. type: Number - contextPath: Netskope.Alert.dst_location description: Application’s city as determined by MaxMind or IP2Location Geolocation database. type: String - contextPath: Netskope.Alert.dst_longitude description: Longitude of the application as determined by MaxMind or IP2Location Geolocation database. type: Number - contextPath: Netskope.Alert.dst_region description: Application’s state or region as determined by MaxMind or IP2Location Geolocation database. type: String - contextPath: Netskope.Alert.dst_timezone description: Destination timezone. type: String - contextPath: Netskope.Alert.dst_zipcode description: Application’s zip code as determined by MaxMind or IP2Location Geolocation database. type: String - contextPath: Netskope.Alert.dstip description: IP address where the destination app is hosted. type: String - contextPath: Netskope.Alert.hostname description: Host name. type: String - contextPath: Netskope.Alert.incident_id description: A unique identifier for an incident or event. type: Number - contextPath: Netskope.Alert.ja3 description: A field indicating JA3 information. type: String - contextPath: Netskope.Alert.ja3s description: A field indicating JA3S information. type: String - contextPath: Netskope.Alert.managed_app description: Whether or not the app in question is managed. type: String - contextPath: Netskope.Alert.managementID description: Management ID. type: String - contextPath: Netskope.Alert.netskope_pop description: Netskope Point of Presence, related to network infrastructure. type: String - contextPath: Netskope.Alert.notify_template description: The template used for notifications or alerts. type: String - contextPath: Netskope.Alert.nsdeviceuid description: Device identifiers on macOS and Windows. type: String - contextPath: Netskope.Alert.organization_unit description: Organization units for which the event correlates to. This ties to user information extracted from Active Directory using the Directory Importer/AD Connector application. type: String - contextPath: Netskope.Alert.os description: Operating system of the host that generated the event. type: String - contextPath: Netskope.Alert.os_version description: Operating system version of the host. type: String - contextPath: Netskope.Alert.other_categories description: Additional categories or labels not specified elsewhere. type: String - contextPath: Netskope.Alert.page description: The URL of the originating page. type: String - contextPath: Netskope.Alert.page_site description: Information about the web page or site being accessed. type: String - contextPath: Netskope.Alert.policy description: Name of the policy configured by an admin. type: String - contextPath: Netskope.Alert.policy_id description: The Netskope internal ID for the policy created by an admin. type: String - contextPath: Netskope.Alert.port description: The network port used for communication. type: String - contextPath: Netskope.Alert.protocol description: The communication protocol or method used. type: String - contextPath: Netskope.Alert.request_id description: Unique request ID for the event. type: Number - contextPath: Netskope.Alert.severity description: Severity used by watchlist and malware alerts. type: String - contextPath: Netskope.Alert.site description: For traffic_type = CloudApp, site = app, and for traffic_type = Web, it will be the second-level domain name + top-level domain name. For example, in “www.cnn.com”, it is “cnn.com”. type: String - contextPath: Netskope.Alert.src_country description: User’s country’s two-letter country code as determined by MaxMind or IP2Location Geolocation database. type: String - contextPath: Netskope.Alert.src_latitude description: Latitude of the user as determined by MaxMind or IP2Location Geolocation database. type: Number - contextPath: Netskope.Alert.src_location description: User’s city as determined by MaxMind or IP2Location Geolocation database. type: String - contextPath: Netskope.Alert.src_longitude description: Longitude of the user as determined by MaxMind or IP2Location Geolocation database. type: Number - contextPath: Netskope.Alert.src_region description: Source state or region as determined by MaxMind or IP2Location Geolocation database. type: String - contextPath: Netskope.Alert.src_time description: A timestamp associated with the source or event. type: Date - contextPath: Netskope.Alert.src_timezone description: Source timezone. Shows the long-format timezone designation. type: String - contextPath: Netskope.Alert.src_zipcode description: Source zip code as determined by MaxMind or IP2Location Geolocation database. type: String - contextPath: Netskope.Alert.srcip description: IP address of the source/user. type: String - contextPath: Netskope.Alert.telemetry_app description: Typically, SaaS app websites use web analytics code within the pages to gather analytic data. When a SaaS app action or page is shown, there is subsequent traffic generated to tracking apps such as doubleclick.net, Optimizely, etc. These tracking apps are listed if applicable in the Telemetry App field. type: String - contextPath: Netskope.Alert.timestamp description: Timestamp when the event/alert happened. Event timestamp in Unix epoch format. type: Number - contextPath: Netskope.Alert.traffic_type description: "Type of the traffic: CloudApp or Web. CloudApp indicates CASB and web indicates HTTP traffic. Web traffic is only captured for inline access method. It is currently not captured for Risk Insights." type: String - contextPath: Netskope.Alert.transaction_id description: Unique ID for a given request/response. type: Number - contextPath: Netskope.Alert.type description: Shows if it is an application event or a connection event. Application events are recorded to track user events inside a cloud app. Connection events show the actual HTTP connection. type: String - contextPath: Netskope.Alert.ur_normalized description: All lowercase user email. type: String - contextPath: Netskope.Alert.url description: URL of the application that the user visited as provided by the log or data plane traffic. type: String - contextPath: Netskope.Alert.user description: User email. type: String - contextPath: Netskope.Alert.useragent description: Browser HTTP user agent header. type: String - contextPath: Netskope.Alert.userip description: IP address of the user. type: String - contextPath: Netskope.Alert.userkey description: User ID or email. type: String - contextPath: Netskope.Alert._client_timeout description: Information related to client timeouts. type: Number - contextPath: Netskope.Alert._dlp_backup_profile description: Information related to DLP (Data Loss Prevention) backup profiles. type: String - contextPath: Netskope.Alert._nsp_dur_back description: Duration information for NSP (Network Security Platform) on the back end. type: Number - contextPath: Netskope.Alert._nsp_dur_front description: Duration information for NSP on the front end. type: Number - contextPath: Netskope.Alert._nsp_retrans_back description: Retransmission information for NSP on the back end. type: Number - contextPath: Netskope.Alert._nsp_retrans_front description: Retransmission information for NSP on the front end. type: Number - contextPath: Netskope.Alert._nsp_rtt_back description: Round-trip time information for NSP on the back end. type: Number - contextPath: Netskope.Alert._nsp_rtt_front description: Round-trip time information for NSP on the front end. type: Number - contextPath: Netskope.Alert._resource_name description: The name associated with a resource. type: String - contextPath: Netskope.Alert._scan_source description: Information indicating the source of a scan. type: String - contextPath: Netskope.Alert._tenant_max_file_size description: The maximum file size allowed for a tenant. type: Number - contextPath: Netskope.Alert.all_policy_matches description: Information related to policy matches. type: String - contextPath: Netskope.Alert.browser_version description: Browser version. type: String - contextPath: Netskope.Alert.file_size description: Size of the file in bytes. type: Number - contextPath: Netskope.Alert.file_type description: File type. type: String - contextPath: Netskope.Alert.md5 description: MD5 of the file. type: String - contextPath: Netskope.Alert.object description: Name of the object which is being acted on. It could be a filename, folder name, report name, document name, etc. type: String - contextPath: Netskope.Alert.object_type description: Type of the object which is being acted on. Object type could be a file, folder, report, document, message, etc. type: String - contextPath: Netskope.Alert.web_universal_connector description: Universal web connector information. type: String - arguments: - auto: PREDEFINED description: Select events by their type. name: event_type predefined: - page - application - audit - infrastructure - network required: true - description: 'Free query to filter the events. For example, "app eq Dropbox". For more information, visit Netskope documentation: https://docs.netskope.com/en/get-events-data.html' name: query - description: 'Restrict events to those that have dates greater than the provided date string (for example "YYYY-MM-DDThh:mm", "1 min ago", "2 weeks ago"). Note that if this argument is provided, you must also provide the ‘end_time’ argument.' name: start_time - description: 'Restrict events to those that have dates less than or equal to the provided date string (for example "YYYY-MM-DDThh:mm", "1 min ago", "2 weeks ago"). Note that if this argument is provided, you must also provide the ‘start_time’ argument. If start_time argument is provided and this argument is not - the default value will be set for now.' name: end_time - description: 'Restrict events to those that were inserted to the system after the provided date string (for example "YYYY-MM-DDThh:mm", "1 min ago", "2 weeks ago"). Note that if this argument is provided, you must also provide the ‘insertion_end_time’ argument.' name: insertion_start_time - description: 'Restrict events to those that were inserted to the system before the provided date string (for example "YYYY-MM-DDThh:mm", "1 min ago", "2 weeks ago"). Note that if this argument is provided, you must also provide the ‘insertion_start_time’ argument. If insertion_start_time argument is provided and this argument is not - the default value will be set for now.' name: insertion_end_time - description: "Page number of paginated results. Minimum value: 1." name: page - defaultValue: "50" description: The maximum number of records to retrieve. name: limit description: Get events extracted from SaaS traffic. You may choose what events to receive with the event_type parameter. You must provide start_time and end_time, or insertion_start_time and insertion_end_time. (Note that if end_time or insertion_end_time aren't provided, the date time would be set as now.) You cannot provide a combination of the options mentioned above. name: netskope-event-list outputs: - contextPath: Netskope.Event._appsession_start description: Netskope event application session start. type: String - contextPath: Netskope.Event._category_id description: Netskope event category ID. type: String - contextPath: Netskope.Event._category_name description: Netskope event category name. type: String - contextPath: Netskope.Event._category_tags description: Netskope event category tags. type: Number - contextPath: Netskope.Event._content_version description: Netskope event content version. type: Number - contextPath: Netskope.Event._correlation_id description: Netskope event correlation ID. type: String - contextPath: Netskope.Event._creation_timestamp description: Netskope event creation timestamp. type: Number - contextPath: Netskope.Event._ef_received_at description: The timestamp indicating when the event was received. type: Date - contextPath: Netskope.Event._event_id description: Netskope event event ID. type: String - contextPath: Netskope.Event._forwarded_by description: Netskope event forwarded by. type: String - contextPath: Netskope.Event._gef_src_dp description: The source data path for the event. type: String - contextPath: Netskope.Event._id description: Netskope event ID. type: String - contextPath: Netskope.Event._insertion_epoch_timestamp description: Netskope event insertion epoch timestamp. type: Number - contextPath: Netskope.Event._nshostname description: The hostname associated with Netskope. type: String - contextPath: Netskope.Event._raw_event_inserted_at description: The date the Netskope raw event was inserted. type: Date - contextPath: Netskope.Event._service_identifier description: Netskope event service identifier. type: String - contextPath: Netskope.Event._session_begin description: The timestamp marking the beginning of a session. type: String - contextPath: Netskope.Event._skip_geoip_lookup description: Netskope event skip GeoIP lookup. type: String - contextPath: Netskope.Event._src_epoch_now description: A numeric value representing the source epoch. type: Number - contextPath: Netskope.Event.access_method description: Netskope event access method. type: String - contextPath: Netskope.Event.action description: Netskope event action. type: String - contextPath: Netskope.Event.activity description: Netskope event activity. type: String - contextPath: Netskope.Event.alert description: Netskope event alert. type: String - contextPath: Netskope.Event.app description: Netskope event app. type: String - contextPath: Netskope.Event.app_session_id description: Netskope event app session ID. type: Number - contextPath: Netskope.Event.appcategory description: Netskope event app category. type: String - contextPath: Netskope.Event.appsuite description: Netskope event app suite. type: String - contextPath: Netskope.Event.browser description: Netskope event browser. type: String - contextPath: Netskope.Event.browser_session_id description: Netskope event browser session ID. type: Number - contextPath: Netskope.Event.category description: Netskope event category. type: String - contextPath: Netskope.Event.cci description: Netskope event Cloud Confidence Index. type: Number - contextPath: Netskope.Event.ccl description: Netskope event Cloud Confidence Levels. type: String - contextPath: Netskope.Event.connection_id description: Netskope event connection ID. type: Number - contextPath: Netskope.Event.count description: Netskope event count. type: Number - contextPath: Netskope.Event.device description: Netskope event device. type: String - contextPath: Netskope.Event.device_classification description: Netskope event device classification. type: String - contextPath: Netskope.Event.dom description: Netskope event Document Object Model (DOM). type: String - contextPath: Netskope.Event.dst_country description: Netskope event destination country. type: String - contextPath: Netskope.Event.dst_latitude description: Netskope event destination latitude. type: Number - contextPath: Netskope.Event.dst_location description: Netskope event destination location. type: String - contextPath: Netskope.Event.dst_longitude description: Netskope event destination longitude. type: Number - contextPath: Netskope.Event.dst_region description: Netskope event destination region. type: String - contextPath: Netskope.Event.dst_timezone description: Netskope event destination timezone. type: String - contextPath: Netskope.Event.dst_zipcode description: Netskope event destination zip code. type: String - contextPath: Netskope.Event.dstip description: Netskope event destination IP. type: String - contextPath: Netskope.Event.hostname description: Netskope event host name. type: String - contextPath: Netskope.Event.incident_id description: Netskope event incident ID. type: Number - contextPath: Netskope.Event.ja3 description: A field indicating JA3 information. type: String - contextPath: Netskope.Event.ja3s description: A field indicating JA3S information. type: String - contextPath: Netskope.Event.managed_app description: Netskope event managed app. type: String - contextPath: Netskope.Event.managementID description: Netskope event management ID. type: String - contextPath: Netskope.Event.netskope_pop description: Netskope event Netskope POP. type: String - contextPath: Netskope.Event.notify_template description: Netskope event notify template. type: String - contextPath: Netskope.Event.nsdeviceuid description: Netskope event Netskope device UID. type: String - contextPath: Netskope.Event.organization_unit description: Netskope event organization unit. type: String - contextPath: Netskope.Event.os description: Netskope event operating system. type: String - contextPath: Netskope.Event.os_version description: Netskope event operating system version. type: String - contextPath: Netskope.Event.other_categories description: Netskope event other categories. type: String - contextPath: Netskope.Event.page description: Netskope event page. type: String - contextPath: Netskope.Event.page_site description: Netskope event page site. type: String - contextPath: Netskope.Event.policy description: Netskope event policy. type: String - contextPath: Netskope.Event.policy_id description: Netskope event policy ID. type: String - contextPath: Netskope.Event.port description: Netskope event port. type: Number - contextPath: Netskope.Event.protocol description: Netskope event protocol. type: String - contextPath: Netskope.Event.request_id description: Netskope event request ID. type: Number - contextPath: Netskope.Event.severity description: Netskope event severity. type: String - contextPath: Netskope.Event.site description: Netskope event site. type: String - contextPath: Netskope.Event.src_country description: Netskope event source country. type: String - contextPath: Netskope.Event.src_latitude description: Netskope event source latitude. type: Number - contextPath: Netskope.Event.src_location description: Netskope event source location. type: String - contextPath: Netskope.Event.src_longitude description: Netskope event source longitude. type: Number - contextPath: Netskope.Event.src_region description: Netskope event source region. type: String - contextPath: Netskope.Event.src_time description: Netskope event source time. type: Date - contextPath: Netskope.Event.src_timezone description: Netskope event source timezone. type: String - contextPath: Netskope.Event.src_zipcode description: Netskope event source zip code. type: String - contextPath: Netskope.Event.srcip description: Netskope event source IP. type: String - contextPath: Netskope.Event.telemetry_app description: Netskope event telemetry app. type: String - contextPath: Netskope.Event.timestamp description: Netskope event timestamp. type: Number - contextPath: Netskope.Event.traffic_type description: Netskope event traffic type. type: String - contextPath: Netskope.Event.transaction_id description: Netskope event transaction ID. type: Number - contextPath: Netskope.Event.type description: Netskope event type. type: String - contextPath: Netskope.Event.ur_normalized description: All lowercase user email. type: String - contextPath: Netskope.Event.url description: Netskope event URL. type: String - contextPath: Netskope.Event.user description: Netskope event user. type: String - contextPath: Netskope.Event.useragent description: Netskope event user agent. type: String - contextPath: Netskope.Event.userip description: Netskope event user IP. type: String - contextPath: Netskope.Event.userkey description: Netskope event user key. type: String - arguments: - description: The URL list ID to update (use netskope-url-list-list command to get URL list ID). name: url_list_id required: true - description: The updated URL list name. name: name required: true - description: The updated URL list items (For Exact - Enter URLs like *.example.com, or IP addresses, separated by a new line. For Regex - Enter URLs like ^client[0-9]\\.google\\.com , ^app\\.slack\\.com/.*/netskope, or ^google.com, separated by a new line). isArray: true name: urls required: true - auto: PREDEFINED description: The updated URL list type. name: list_type predefined: - exact - regex required: true - auto: PREDEFINED defaultValue: "false" description: Whether to deploy URL list changes or not. name: deploy predefined: - "True" - "False" - auto: PREDEFINED defaultValue: "False" description: Whether to overwrite the URL list or not. name: is_overwrite predefined: - "True" - "False" description: Update the URL list with the values provided. Note that this command overrides the list. name: netskope-url-list-update outputs: - contextPath: Netskope.URLList.id description: Netskope URL list ID. type: Number - contextPath: Netskope.URLList.name description: Netskope URL list name. type: String - contextPath: Netskope.URLList.data.urls description: Netskope URL list data URLs. type: String - contextPath: Netskope.URLList.data.type description: Netskope URL list data type. type: String - contextPath: Netskope.URLList.data.json_version description: Netskope URL list data JSON version. type: Number - contextPath: Netskope.URLList.modify_by description: Netskope URL list modify by. type: String - contextPath: Netskope.URLList.modify_time description: Netskope URL list modify time. type: Date - contextPath: Netskope.URLList.modify_type description: Netskope URL list modify type. type: String - contextPath: Netskope.URLList.pending description: Netskope URL list pending. type: Number - arguments: - description: The unique name for the URL list. name: name required: true - description: The URL list items (For Exact - Enter URLs like *.example.com, or IP addresses, separated by a new line. For Regex - Enter URLs like ^client[0-9]\\.google\\.com , ^app\\.slack\\.com/.*/netskope, or ^google.com, separated by a new line). isArray: true name: urls required: true - auto: PREDEFINED description: The URL list type. name: list_type predefined: - exact - regex required: true - auto: PREDEFINED defaultValue: "false" description: Whether to deploy URL list changes or not. name: deploy predefined: - "True" - "False" description: Create a new URL list. name: netskope-url-list-create outputs: - contextPath: Netskope.URLList.id description: Netskope URL list ID. type: Number - contextPath: Netskope.URLList.name description: Netskope URL list name. type: String - contextPath: Netskope.URLList.data.urls description: Netskope URL list data URLs. type: String - contextPath: Netskope.URLList.data.type description: Netskope URL list data type. type: String - contextPath: Netskope.URLList.data.json_version description: Netskope URL list data JSON version. type: Number - contextPath: Netskope.URLList.modify_by description: Netskope URL list modify by. type: String - contextPath: Netskope.URLList.modify_time description: Netskope URL list modify time. type: Date - contextPath: Netskope.URLList.modify_type description: Netskope URL list modify type. type: String - contextPath: Netskope.URLList.pending description: Netskope URL list pending. type: Number - arguments: - description: The URL list ID to get. name: url_list_id - auto: PREDEFINED description: Get a list of only applied or pending URL lists. name: pending predefined: - applied - pending - description: "Comma-separated data values to return in response call (for example: name, id, data, modify_by, modify_time, modify_type, pending). Defaults to all values." isArray: true name: field - description: Whether to retrieve all results or not. name: all_results defaultValue: "false" auto: PREDEFINED predefined: - "True" - "False" - defaultValue: "50" description: The maximum number of records to retrieve. name: limit description: Get all URL lists or a specific URL list by specifying the list ID. name: netskope-url-lists-list outputs: - contextPath: Netskope.URLList.id description: Netskope URL list ID. type: Number - contextPath: Netskope.URLList.name description: Netskope URL list name. type: String - contextPath: Netskope.URLList.data.urls description: Netskope URL list data URLs. type: String - contextPath: Netskope.URLList.modify_by description: Netskope URL list modify by. type: String - contextPath: Netskope.URLList.modify_time description: Netskope URL list modify time. type: Date - contextPath: Netskope.URLList.modify_type description: Netskope URL list modify type. type: String - contextPath: Netskope.URLList.pending description: Netskope URL list pending status. type: String - arguments: - description: The URL list ID to delete (use netskope-url-list-list to get the URL list ID). name: url_list_id required: true - auto: PREDEFINED defaultValue: "false" description: Whether to deploy URL list changes or not. name: deploy predefined: - "True" - "False" description: Delete a URL list by the list ID. name: netskope-url-list-delete outputs: - contextPath: Netskope.URLList.id description: Netskope URL list ID. type: Number - contextPath: Netskope.URLList.name description: Netskope URL list name. type: String - arguments: - description: 'Filter the Netskope user by ''key eq value'' template. Filter by the given predefined values. For example: "userName eq someUserName" OR "externalId eq User-Ext_id".' name: filter auto: PREDEFINED predefined: - 'active' - 'emails.value' - 'externalId' - 'userName' - description: "Page number of paginated results. Minimum value: 1." name: page - defaultValue: "50" description: The maximum number of records to retrieve. name: limit description: Get information about Netskope SCIM users. The command provides a list of users who have been imported into the Netskope tenant through SCIM integration. Users imported through other methods, such as manual CSV import or manual creation, will not be included in the returned results. name: netskope-client-list outputs: - contextPath: Netskope.Client.id description: Netskope client ID. type: Number - contextPath: Netskope.Client.name description: Netskope client name. - contextPath: Netskope.Client.given_name description: Netskope client first_name of the SCIM User. type: String - contextPath: Netskope.Client.family_name description: Netskope client last_name of the SCIM User.. type: String - contextPath: Netskope.Client.userName description: Netskope client username. type: String - contextPath: Netskope.Client.externalId description: Netskope client external ID. type: String - contextPath: Netskope.Client.active description: Netskope client activate. type: Boolean - contextPath: Netskope.Client.emails description: Netskope client emails. type: String - arguments: - description: The URL list ID to update (use netskope-url-list-list command to get URL list ID). name: url_list_id required: true - description: The updated URL list items (For Exact - Enter URLs like *.example.com, or IP addresses, separated by a new line. For Regex - Enter URLs like ^client[0-9]\\.google\\.com , ^app\\.slack\\.com/.*/netskope, or ^google.com, separated by a new line). isArray: true name: urls required: true - auto: PREDEFINED description: The updated URL list type. name: list_type predefined: - exact - regex required: true - auto: PREDEFINED defaultValue: "false" description: Whether to deploy URL list changes or not. name: deploy predefined: - "True" - "False" description: Update the URL list with the values provided. Note that this command appends the list. name: netskope-url-list-add outputs: - contextPath: Netskope.URLList.id description: Netskope URL list ID. type: Number - contextPath: Netskope.URLList.name description: Netskope URL list name. type: String - contextPath: Netskope.URLList.data.urls description: Netskope URL list data URLs. type: String - contextPath: Netskope.URLList.data.type description: Netskope URL list data type. type: String - contextPath: Netskope.URLList.data.json_version description: Netskope URL list data JSON version. type: Number - contextPath: Netskope.URLList.modify_by description: Netskope URL list modify by. type: String - contextPath: Netskope.URLList.modify_time description: Netskope URL list modify time. type: Date - contextPath: Netskope.URLList.modify_type description: Netskope URL list modify type. type: String - contextPath: Netskope.URLList.pending description: Netskope URL list pending. type: Number - arguments: [] description: Returns the list of fields for an incident type. name: get-mapping-fields - arguments: [] description: Updates the remote incident or detection with local incident or detection changes. This method is only used for debugging purposes and will not update the current incident or detection. name: update-remote-system - arguments: - description: The ticket ID. name: id required: true - description: Retrieves entries that were created after lastUpdate. name: lastUpdate required: true description: Gets remote data from a remote incident. This method does not update the current incident, and should be used for debugging purposes. name: get-remote-data - arguments: - description: A date string in local time representing the last time the incident was updated. The incident is only returned if it was modified after the last update time. name: lastUpdate description: Gets the list of incidents that were modified since the last update time. Note that this method is here for debugging purposes. The get-modified-remote-data command is used as part of a Mirroring feature, which is available in Cortex XSOAR from version 6.1. name: get-modified-remote-data dockerimage: demisto/python3:3.12.13.10116658 isfetch: true ismappable: true isremotesyncin: true isremotesyncout: true runonce: false script: "" subtype: python3 type: python fromversion: 6.9.0 tests: - Netskope_V2_Test