NetskopeWebTransactions_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (147 columns)

Source: Connector definition

Column Name Type Description
Bytes int bytes.
CIp string c-ip.
CsBytes int cs-bytes.
CsContentType string cs-content-type.
CsDns string cs-dns.
CsHost string cs-host.
CsMethod string cs-method.
CsReferer string cs-referer.
CsUri string cs-uri.
CsUriPort int cs-uri-port.
CsUriQuery string cs-uri-query.
CsUriScheme string cs-uri-scheme.
CsUserAgent string cs-user-agent.
CsUsername string cs-username.
Date string date.
RsStatus int rs-status.
ScBytes int sc-bytes.
ScContentType string sc-content-type.
ScStatus int sc-status.
SIp string s-ip.
Time string time.
TimeGenerated datetime The timestamp (UTC) reflecting the time in which the event was generated.
TimeTaken int time-taken.
XCategory string x-category.
XCategoryId int x-category-id.
XCBrowser string x-c-browser.
XCBrowserVersion int x-c-browser-version.
XCCountry string x-c-country.
XCDevice string x-c-device.
XCLatitude real x-c-latitude.
XClientSslErr string x-client-ssl-err.
XCLocalTime string x-c-local-time.
XCLocation string x-c-location.
XCLongitude real x-c-longitude.
XCOs string x-c-os.
XCRegion string x-c-region.
XCsAccessMethod string x-cs-access-method.
XCsApp string x-cs-app.
XCsAppActivity string x-cs-app-activity.
XCsAppCategory string x-cs-app-category.
XCsAppCci int x-cs-app-cci.
XCsAppCcl string x-cs-app-ccl.
XCsAppFromUser string x-cs-app-from-user.
XCsAppInstanceId string x-cs-app-instance-id.
XCsAppInstanceName string x-cs-app-instance-name.
XCsAppInstanceTag string x-cs-app-instance-tag.
XCsAppObjectId string x-cs-app-object-id.
XCsAppObjectName string x-cs-app-object-name.
XCsAppObjectType string x-cs-app-object-type.
XCsAppSuite string x-cs-app-suite.
XCsAppTags string x-cs-app-tags.
XCsAppToUser string x-cs-app-to-user.
XCsConnectHost string x-cs-connect-host.
XCsConnectPort string x-cs-connect-port.
XCsConnectUserAgent string x-cs-connect-user-agent.
XCsDomainFrontedSni string x-cs-domain-fronted-sni.
XCsDstIp string x-cs-dst-ip.
XCsDstPort int x-cs-dst-port.
XCsHttpVersion string x-cs-http-version.
XCsIpConnectXff string x-cs-ip-connect-xff.
XCsIpXff string x-cs-ip-xff.
XCsPageId string x-cs-page-id.
XCsSessionId string x-cs-session-id.
XCsSite string x-cs-site.
XCsSni string x-cs-sni.
XCsSrcIp string x-cs-src-ip.
XCsSrcIpEgress string x-cs-src-ip-egress.
XCsSrcPort int x-cs-src-port.
XCsSslCipher string x-cs-ssl-cipher.
XCsSslEngineAction string x-cs-ssl-engine-action.
XCsSslEngineActionReason string x-cs-ssl-engine-action-reason.
XCsSslFrontingError string x-cs-ssl-fronting-error.
XCsSslHandshakeError string x-cs-ssl-handshake-error.
XCsSslJa3 string x-cs-ssl-ja3.
XCsSslVersion string x-cs-ssl-version.
XCsTimestamp long x-cs-timestamp.
XCsTrafficType string x-cs-traffic-type.
XCsTunnelId string x-cs-tunnel-id.
XCsUriPath string x-cs-uri-path.
XCsUrl string x-cs-url.
XCsUserIp string x-cs-userip.
XCZipcode int x-c-zipcode.
XError string x-error.
XOtherCategory string x-other-category.
XOtherCategoryId string x-other-category-id.
XPolicyAction string x-policy-action.
XPolicyDstHost string x-policy-dst-host.
XPolicyDstHostSource string x-policy-dst-host-source.
XPolicyDstIp string x-policy-dst-ip.
XPolicyJustificationReason string x-policy-justification-reason.
XPolicyJustificationType string x-policy-justification-type.
XPolicyName string x-policy-name.
XPolicySrcIp string x-policy-src-ip.
XRCertEndDate string x-r-cert-enddate.
XRCertExpired string x-r-cert-expired.
XRCertIncompleteChain string x-r-cert-incomplete-chain.
XRCertIssuerCn string x-r-cert-issuer-cn.
XRCertMismatch string x-r-cert-mismatch.
XRCertRevocationCheck string x-r-cert-revocation-check.
XRCertRevoked string x-r-cert-revoked.
XRCertSelfSigned string x-r-cert-self-signed.
XRCertStartDate string x-r-cert-startdate.
XRCertSubjectCn string x-r-cert-subject-cn.
XRCertUntrustedRoot string x-r-cert-untrusted-root.
XRCertValid string x-r-cert-valid.
XRequestId string x-request-id.
XRsFileCategory string x-rs-file-category.
XRsFileLanguage string x-rs-file-language.
XRsFileMd5 string x-rs-file-md5.
XRsFileSha256 string x-rs-file-sha256.
XRsFileSize int x-rs-file-size.
XRsFileType string x-rs-file-type.
XScNotificationName string x-sc-notification-name.
XSCountry string x-s-country.
XSCustomSigningCaError string x-s-custom-signing-ca-error.
XSDpName string x-s-dp-name.
XServerSslErr string x-server-ssl-err.
XSLatitude real x-s-latitude.
XSLocation string x-s-location.
XSLongitude real x-s-longitude.
XSrDstIp string x-sr-dst-ip.
XSrDstPort int x-sr-dst-port.
XSRegion string x-s-region.
XSrHeadersName string x-sr-headers-name.
XSrHeadersValue string x-sr-headers-value.
XSrSrcIp string x-sr-src-ip.
XSrSrcPort string x-sr-src-port.
XSrSslCipher string x-sr-ssl-cipher.
XSrSslClientCertificateError string x-sr-ssl-client-certificate-error.
XSrSslEngineAction string x-sr-ssl-engine-action.
XSrSslEngineActionReason string x-sr-ssl-engine-action-reason.
XSrSslHandshakeError string x-sr-ssl-handshake-error.
XSrSslJa3S string x-sr-ssl-ja3s.
XSrSslMalformedSsl string x-sr-ssl-malformed-ssl.
XSrSslVersion string x-sr-ssl-version.
XSslBypass string x-ssl-bypass.
XSslBypassReason string x-ssl-bypass-reason.
XSslPolicyAction string x-ssl-policy-action.
XSslPolicyCategories string x-ssl-policy-categories.
XSslPolicyDstHost string x-ssl-policy-dst-host.
XSslPolicyDstHostSource string x-ssl-policy-dst-host-source.
XSslPolicyDstIp string x-ssl-policy-dst-ip.
XSslPolicyName string x-ssl-policy-name.
XSslPolicySrcIp string x-ssl-policy-src-ip.
XSZipcode int x-s-zipcode.
XTransactionId string x-transaction-id.
XType string x-type.

Solutions (2)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Netskope Web Transaction Connector (via Blob Storage)

Content Items Using This Table (13)

Analytic Rules (10)

In solution NetskopeWebTx:

Analytic Rule Selection Criteria
Netskope - Anomalous User Behavior (High Volume from Unmanaged Device)
Netskope - Data Movement Tracking (Upload/Download Monitoring)
Netskope - Excessive Downloads Detection (Spike vs Baseline)
Netskope - Heavy Personal Cloud Storage Usage (Shadow IT)
Netskope - Impossible Travel Detection (Two Countries in Less Than 1 Hour)
Netskope - Large Outbound Data Transfer / Sensitive Upload (DLP)
Netskope - New Risky App Access vs 7-Day Baseline
Netskope - Repeated or Critical Policy Violations
Netskope - Suspicious Network Context (Unusual IPs/Geo/Ports)
Netskope - Unsanctioned/Risky Cloud App Access (Shadow IT)

Workbooks (3)

In solution NetskopeWebTx:

Workbook Selection Criteria
NetskopeWebTx_Workbook

In solution Netskopev2:

Workbook Selection Criteria
NetskopeCCFWebtxDashboard

GitHub Only:

Workbook Selection Criteria
NetskopeWebTx_Workbook

Parsers Using This Table (2)

Other Parsers (2)

Parser Solution Selection Criteria
NetskopeCCFWebTransactions Netskopev2
NetskopeWebtx NetskopeWebTx

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index