Skip to main content
Skip table of contents

Netskope : Network Event

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

Base RuleNetwork TrafficGeneral Traffic Log
Netskope : Network Traffic AllowedSub RuleNetwork AllowTraffic Allowed by Network Firewall
Netskope : Network Traffic DeniedSub RuleNetwork DenyTraffic Denied by Network Firewall

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData Type
Device vendorN/AN/A
device productN/A N/A
Device versionN/AN/A
Device event class id<vmid>Text/String
Event nameN/AN/A
Severity of the event<severity>Text/String
sourceAddress<sip>IP Address
destinationAddress<dip>IP Address
requestClientApplicationN/AN/A
sourceServiceName<process>Text/String
sourceUserName<login>Text/String
sourceHostName<sname>Text/String
sourcePort<sport>Number
startTimeN/AN/A
endTimeN/AN/A
destinationPort<dport>Number
timestampN/AN/A
cclN/AN/A
cciN/AN/A
clientBytes<bytesin>Number
serverBytes<bytesout>Number
deviceN/AN/A
osN/AN/A
client_packets<packetsin>Number
policy<policy>Text/String
traffic_typeN/AN/A
action<action>
<tag1>
Text/String
requestMethodN/AN/A
osVersionN/AN/A
network_Session_Id<session>Text/String
transportProtocol<protname>Text/String
server_packets<packetsout>Number
sessionDuration<seconds>Number
tunnel_typeN/AN/A
tunnel_up_timeN/AN/A
tunnel_idN/AN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.