Netskope : Policy Threat Event

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

Netskope : Policy Threat Event

Base Rule

Activity

General Activity

Netskope : Policy Threat Alert

Sub Rule

Activity

General Alert Log Message

Netskope : Blocked By Policy

Sub Rule

Failed Activity

Web Activity Blocked

Netskope : Quarantined File/Action

Sub Rule

Activity

Quarantine

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Device Vendor

N/A

N/A

Device Product

N/A 

N/A

Device Version

N/A

N/A

Device Event Class ID

<vmid>

Text/String

Name of the event

<threatname>

Text/String

Severity of the event

<severity>

Text/String

accessMethod

N/A

N/A

action

<result>
<tag1>

Text/String

appcategory

<subject>

Text/String

browser

N/A

N/A

device

N/A

N/A

os

N/A

N/A

requestClientApplication

N/A

N/A

sourceServiceName

<process>

Text/String

dst

<dip>

IP Address

src

<sip

IP Address

suser

<login>

Text/String

timestamp

N/A

N/A

url

<url>

Text/String