Skip to content

Integrate Netskope SSE

You can integrate Netskope SSE with Sophos XDR so that it sends data to Sophos for analysis. The integration uses a data collector, which receives third-party data and sends it to the Sophos Data Lake.

Key steps

The key steps in a Netskope SSE integration are as follows:

  • Install and configure a data collector if you haven't already done so.
  • Configure Netskope SSE to send data to the data collector.

Requirements

The following is required for Netskope SSE configuration:

Add a Netskope SSE integration

To integrate Netskope SSE, you must first install a Sophos XDR data collector, then configure Netskope to send logs to it.

Install and configure a data collector

Netskope SSE must be configured to send logs to the Sophos XDR data collector. Logs are filtered and correlated in real-time for various security event observations. Go to Data collectors and follow the guide for creating a data collector if you haven't already done so.

Configure logging and enable monitoring

When the data collector is ready, you can configure Netskope SSE to send us data.

To set up event forwarding via syslog, do as follows:

  1. Follow the steps in Netskope's own guide: Log Shipper Module.
  2. Choose the following options during setup:

    • Plugin: Choose Syslog.
    • Mapping: Choose Syslog Defaults Mapping.
  3. Be sure the configured IP address matches the Sophos XDR data collector's server IP address.

Your Netskope SSE data should now appear in the Sophos Data Lake after validation.

Configuration notes

Keep the following in mind during Netskope SSE configuration:

  • The Cloud Log Shipper pulls logs from Netskope's APIs and forwards them via syslog, in CEF format.
  • You can configure multiple instances of Netskope to send data to Sophos via the same data collector. After you finish integration, repeat the steps in this section for your other instances of Netskope.

Additional resources

For more information on configuring Netskope SSE, see the following documents: