Netskope: Malsite Event

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

Netskope: Malsite Event

Base Rule

Activity

Potentially Threatening URL Allowed

NetSkope: Malsite : Traffic Denied To Malcious URL

Sub Rule

Network Deny

Traffic Denied by Network Firewall

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Device Vendor

N/A 

N/A

Device Product

N/A 

N/A

Device Version

 N/A

N/A

Device Event Class ID

<vmid>

Text/String

Name of the event

 N/A

N/A

Severity of the event

<severity>

Text/String

accessMethod

 N/A

N/A

action

<action>
<tag1>

Text/String

appcategory

<subject>

Text/String

browser

 N/A

N/A

device

 N/A

N/A

dst

<dip>

IP Address

hostname

<dname>

Text/String

msAppSessionId

 <session>

Text/String

msCategory

<threatname>

Text/String

msId

 <threatid>

N/A

msMatchField

 N/A

N/A

os

 N/A

N/A

policy

<policy>

Text/String

referer

 N/A

N/A

src

<sip>

IP Address

suser

<login>

Text/String

timestamp

 N/A

N/A

url

<url>

Text/String