↳ GitHub sourceConnector

Netskope Web Transactions (via Blob Storage)

Description

The Netskope Web Transactions data connector enables ingestion of web transaction logs from Netskope into Microsoft Sentinel using Netskope Log Streaming (NLS) capability. Web transaction logs provide detailed visibility into all web traffic processed by Netskope, including user activity, application usage, URL categories, policy actions, and network metadata. This connector uses Azure Blob Storage and Event Grid to ingest logs that Netskope streams to your storage account.
Declared status
1
Declared author / publisher
Netskope

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace
Read permissions to shared keys for the workspace are required.
Keys
Workspace
Subscription permissions
You need permissions to create the data flow resources:
- Storage queues (notification queue and dead-letter queue)
- Event Grid topic and subscription (to send 'blob created event' notifications)
- Role assignments (to grant access for Microsoft Sentinel app to the blob container and storage queues)
Netskope Log Streaming Configuration
Configure Netskope Log Streaming (NLS) to send Web Transaction logs to your Azure Blob Storage container. Follow the [Netskope NLS documentation](https://docs.netskope.com/en/log-streaming) for setup instructions.

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Connect Netskope Web Transaction Logs to Microsoft Sentinel
To enable the Netskope Web Transactions Logs for Microsoft Sentinel, provide the required information below and click on Connect. **Prerequisites:** 1. Configure Netskope NLS to send Web Transaction logs to an Azure Blob Storage container 2. Ensure you have the required permissions on the storage account
Blob Container URL
Blob Folder Name (Optional)
Storage Account Location
Storage Account Resource Group Name
Storage Account Subscription ID
Event Grid Topic Name (if exists)
The data flow uses Event Grid to send 'blob-created event' notifications. There can be only one Event Grid topic per storage account. Go to your storage account's 'Events' section. If you already have a topic, provide its name. Otherwise, leave empty to create a new one.
toggle

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
NetskopeWebTxConnector
Additional source files 2Solutions/NetskopeWebTx/Data Connectors/NetskopeWebTx_CCF/NetskopeWebtx_connectorDefinition.jsonsource ↗Solutions/NetskopeWebTx/Data/Solution_NetskopeWebTx.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.