↳ Source GitHubConnecteur
Netskope Alerts & Events (via Log Streaming)
Description
The Netskope Alerts & Events data connector enables ingestion of alert and event logs from Netskope into Microsoft Sentinel using Netskope Log Streaming (NLS) capability. Alerts & Events logs provide visibility into DLP incidents, malware and threat detections, policy violations, anomalous behavior, compromised credentials, and application activity across the Netskope Security Cloud.
This connector uses Azure Blob Storage and Event Grid to ingest the gzip-compressed CSV logs that Netskope streams to your storage account. The logs are mapped to columns positionally, so the Netskope Log Streaming configuration must use the matching field order.
- Statut déclaré
- 1
- Auteur / éditeur déclaré
- Netskope
Sources déclarées
Métadonnées du fichier source. Aucune dépendance déduite du KQL.
Types de données
Permissions déclarées
Read and Write permissions are required.
Workspace
Workspace
Read permissions to shared keys for the workspace are required.
Keys
Workspace
Subscription permissions
You need permissions to create the data flow resources: - Storage queues (notification queue and dead-letter queue) - Event Grid topic and subscription (to send 'blob created event' notifications) - Role assignments (to grant access for Microsoft Sentinel app to the blob container and storage queues)
Netskope Log Streaming Configuration
Configure Netskope Log Streaming (NLS) to send Alerts & Events logs to your Azure Blob Storage container. Follow the [Netskope NLS documentation](https://docs.netskope.com/en/netskope-help/data-security/netskope-log-streaming/) for setup instructions.
Instructions du connecteur
Contenu publié dans le dépôt. Consultez le fichier original pour l’ensemble des paramètres.
Connect Netskope Alerts & Events Logs to Microsoft Sentinel
To enable the Netskope Alerts & Events Logs for Microsoft Sentinel, provide the required information below and click on Connect.
**Prerequisites:**
1. Configure Netskope NLS to send Alerts & Events logs to an Azure Blob Storage container
2. Ensure you have the required permissions on the storage account
Blob Container URL
Blob Folder Name (Optional)
Storage Account Location
Storage Account Resource Group Name
Storage Account Subscription ID
Event Grid Topic Name (if exists)
The data flow uses Event Grid to send 'blob-created event' notifications. There can be only one Event Grid topic per storage account. Go to your storage account's 'Events' section. If you already have a topic, provide its name. Otherwise, leave empty to create a new one.
toggle
Contenus associés
Liens établis à partir des identifiants déclarés et des manifests des solutions.
Traçabilité de la source
GitHubLes valeurs affichées proviennent des fichiers du dépôt Azure/Azure-Sentinel. Elles décrivent le modèle publié, pas la configuration de votre workspace.
- Commit
9800e51↗- Identifiant source
NetskopeAlertEventsConnector
GSTEP / SUIVI DU CATALOGUE
Ajouté au catalogue : 16 sept. 2026 · 05:49 UTC
Dernier changement observé : 16 sept. 2026 · 05:49 UTC