Netskope SSE
You can integrate Netskope SSE with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Netskope SSE product overview
Netskope Security Service Edge (SSE) is a cloud-native platform that converges secure web gateway (SWG), cloud access security broker (CASB), and zero trust network access (ZTNA) to secure access to the web, cloud services, and private applications from any location, with data-centric threat and data protection.
What we ingest
Sophos XDR collects Netskope data using the Netskope Cloud Log Shipper, which pulls events from the Netskope APIs and forwards them as CEF over syslog to a Sophos XDR data collector. The following log categories are collected:
- Web and cloud activity: Web transactions, proxy connections, and malicious-site visits.
- Malware detections: Malware detections and remediation actions.
- Threat and risk alerts: Compromised credentials, user behavior analytics (UBA), watchlist, and intrusion prevention (IPS) detections.
- Policy violations: Policy enforcement detections.
- Administrative activity: Administrative and configuration audit events.
- Network traffic1: Network connection and tunnel events.
Event and data types
We ingest the following event and data types from Netskope SSE:
- Web and cloud activity: Web transactions, proxy connections, and malicious-site visits, including the URL, action, application, and user. Normalized to HTTP telemetry.
- Malware detections: Malware detections and remediation actions, including the file and verdict. Normalized to antivirus telemetry.
- Threat and risk alerts: Compromised credentials, user behavior analytics (UBA), watchlist, and intrusion prevention (IPS) detections. Normalized to third-party security alert telemetry.
- Policy violations: Policy enforcement detections, including the rule, action, and endpoints. Normalized to network intrusion detection telemetry.
- Administrative activity: Administrative and configuration audit events, with user and action. Normalized to authentication telemetry.
- Network traffic1: Network connection and tunnel events, including source and destination and bytes. Normalized to netflow telemetry.
Data provided by this integration
Data provided by Netskope SSE gets normalized to the following schemas:
antivirusauthhttpnetflow1nidsthirdpartyalert
For more information about using schemas in Data Lake Search, see Schemas and logical types.
Vendor documentation
-
Netflow telemetry is only available with a Sophos Next-Gen SIEM subscription. See Sophos Next-Gen SIEM overview. ↩↩↩