Netskope : Page Events Detected

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

Netskope : Page Events Detected

Base Rule

Information

General Information Log Message

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Device vendor

 N/A

N/A

device product

 N/A

N/A

Device version

 N/A

N/A

Device event class id

<vmid>

Text/String

Event name

 N/A

N/A

Severity of the event

<severity>

Text/String

sourceAddress

<sip>

IP Address

destinationAddress

<dip>

IP Address

requestClientApplication

 N/A

N/A

sourceServiceName

 <process>

Text/String

sourceUserName

<login>

Text/String

timestamp

 N/A

N/A

ccl

 N/A

N/A

cci

 N/A

N/A

appcategory

<subject>

Text/String

clientBytes

<bytesin>

Number

serverBytes

<bytesout>

Number

pageStarttime

 N/A

N/A

pageEndtime

 N/A

N/A

device

 N/A

N/A

os

 N/A

N/A

browser

 N/A

N/A

url

<url>

Text/String

pageId

 N/A

N/A

page

 N/A

N/A