↳ GitHub sourceConnector

Netskope Alerts and Events (via Codeless Connector Framework)

Description

Netskope Security Alerts and Events
Declared author / publisher
Netskope

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace
Netskope organisation url
The Netskope data connector requires you to provide your organisation url. You can find your organisation url by signing into the Netskope portal.
Netskope API key
The Netskope data connector requires you to provide a valid API key. You can create one by following the [Netskope documentation](https://docs.netskope.com/en/rest-api-v2-overview-312207/).

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

STEP 1 - Create a Netskope API key.
Follow the [Netskope documentation](https://docs.netskope.com/en/rest-api-v2-overview-312207/) for guidance on this step.
STEP 2 - Enter your Netskope product Details
Enter your Netskope organisation url & API Token below:
Organisation Url
API Key
Netskope Alerts Remediation
Yes
No
Netskope Alerts Uba
Yes
No
Netskope Alerts Security Assessment
Yes
No
Netskope Alerts Quarantine
Yes
No
Netskope Alerts Policy
Yes
No
Netskope Alerts Malware
Yes
No
Netskope Alerts Malsite
Yes
No
Netskope Alerts DLP
Yes
No
Netskope Alerts CTEP
Yes
No
Netskope Alerts Watchlist
Yes
No
Netskope Alerts Compromised Credentials
Yes
No
Netskope Alerts Content
Yes
No
Netskope Alerts Device
Yes
No
Netskope Events Application
Yes
No
Netskope Events Audit
Yes
No
Netskope Events Connection
Yes
No
Netskope Events DLP
Yes
No
Netskope Events Endpoint
Yes
No
Netskope Events Infrastructure
Yes
No
Netskope Events Network
Yes
No
Netskope Events Page
Yes
No
OPTIONAL: Specify the Index the API uses.
**Configuring the index is optional and only required in advanced scenario's.** Netskope uses an [index](https://docs.netskope.com/en/using-the-rest-api-v2-dataexport-iterator-endpoints/#how-do-iterator-endpoints-function) to retrieve events. In some advanced cases (consuming the event in multiple Microsoft Sentinel workspaces, or pre-fatiguing the index to only retrieve recent data), a customer might want to have direct control over the index.
Index
STEP 3 - Click Connect
Verify all fields above were filled in correctly. Press the Connect to connect Netskope to Microsoft Sentinel.

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
NetskopeAlertsEvents
Additional source files 2Solutions/Netskopev2/Data Connectors/NetskopeAlertsEvents_RestAPI_CCP/NetskopeAlertsEvents_ConnectorDefination.jsonsource ↗Solutions/Netskopev2/Data/Solution_Netskope.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.