Document toolboxDocument toolbox

casb.netskope

Introduction

The tags beginning with casb.netskope identify events generated by CASB Netskope.

Valid tags and data tables

The full tag must have 3 levels. The first two are fixed as casb.netskope. The third level identifies the type of events sent.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Netskope CASB (Cloud Access Security Broker)

casb.netskope

casb.netskope

casb.netskope.alert

casb.netskope.alert

casb.netskope.application

casb.netskope.application

casb.netskope.audit

casb.netskope.audit

casb.netskope.client

casb.netskope.client

casb.netskope.compromisedcredential

casb.netskope.compromisedcredential

casb.netskope.incident

casb.netskope.incident

casb.netskope.infrastructure

casb.netskope.infrastructure

casb.netskope.malsite

casb.netskope.malsite

casb.netskope.malware

casb.netskope.malware

casb.netskope.network

casb.netskope.network

casb.netskope.page

casb.netskope.page

casb.netskope.policy

casb.netskope.policy

casb.netskope.transaction_events

casb.netskope.transaction_events

casb.netskope.uba

casb.netskope.uba

For more information, read more About Devo tags.

How is the data sent to Devo?

Logs generated by CASB Netskope are forwarded to Devo using a dedicated collector. Contact us if you need to forward these events to your Devo domain so we can guide you through the process.

Table structure

These are the fields displayed in these tables: