⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Publisher | Netskope |
| Support Tier | Partner |
| Support Link | https://www.netskope.com/services#support |
| Categories | Security - Cloud Security,Security - Threat Protection |
| Version | 3.0.0 |
| Author | Netskope |
| First Published | 2026-06-17 |
| Last Updated | 2026-06-17 |
| Solution Folder | NetskopeAlertEvents |
The Netskope Alerts & Events solution enables streaming of alert and event logs from Netskope to Microsoft Sentinel via Azure Blob Storage and Event Grid. It provides visibility into DLP incidents, malware and threat detections, policy violations, anomalous behavior, and cloud application activity across the Netskope Security Cloud.
Included Content:
This solution provides 1 data connector(s):
This solution uses 1 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
NetskopeAlertEvents_CL |
Netskope Alerts & Events (via Log Streaming) | Analytics, Workbooks |
This solution includes 5 content item(s):
| Content Type | Count |
|---|---|
| Analytic Rules | 3 |
| Workbooks | 1 |
| Parsers | 1 |
| Name | Severity | Tactics | Tables Used |
|---|---|---|---|
| Netskope - DLP Incident Spike | High | Exfiltration, Collection | NetskopeAlertEvents_CL |
| Netskope - High Severity Alert | High | InitialAccess, Exfiltration | NetskopeAlertEvents_CL |
| Netskope - Suspicious Application Activity (Low Confidence / Risky App) | Medium | Exfiltration, CommandAndControl | NetskopeAlertEvents_CL |
| Name | Tables Used |
|---|---|
| NetskopeAlertEvents_Workbook | NetskopeAlertEvents_CL |
| Name | Description | Tables Used |
|---|---|---|
| NetskopeAlertEvents | - | NetskopeAlertEvents_CL (read) |
📄 Source: NetskopeAlertEvents/README.md
The Netskope Alerts & Events solution streams alert and event logs from the
Netskope Security Cloud into Microsoft Sentinel using Netskope Log Streaming (NLS).
Logs are delivered to an Azure Blob Storage container as gzip-compressed,
positional CSV and ingested by Sentinel's Codeless Connector Framework (CCF)
Blob Storage connector into the custom Log Analytics table
NetskopeAlertEvents_CL. The DCR stream declares 254 columns in a fixed
order; NLS must emit fields in that same order because values are mapped by
position.
The solution provides visibility into:
Included content
| Content | Count | Notes |
|---|---|---|
| Data Connector | 1 | CCF Blob Storage connector (NetskopeAlertEventsConnector) |
| Custom Table | 1 | NetskopeAlertEvents_CL |
| Parser | 1 | NetskopeAlertEvents (saved function) |
| Workbook | 1 | Netskope Alerts & Events Dashboard |
| Analytic Rules | 3 | High Severity Alert, Suspicious Application Activity, DLP Incident Spike |
Netskope Log Streaming
|
v
Azure Blob Storage (gzip-compressed CSV)
|
v
Event Grid (Blob Created notifications)
|
v
Storage Queue (notification queue + dead-letter queue)
|
v
Sentinel CCF Connector (Service Principal auth + DCR transform)
|
v
NetskopeAlertEvents_CL (Log Analytics custom table)
appId 4f05ce56-95b6-4612-9d98-a45c8cc33f9f) in your tenant.In the Netskope admin console, create a Log Streaming configuration that streams Alerts and Events to your Azure Blob Storage container as gzip-compressed CSV.
[Content truncated...]
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.0 | 17-06-2026 | Initial solution release. Netskope Alerts & Events CCF (Blob Storage) connector, custom table NetskopeAlertEvents_CL, parser, 1 workbook, and 3 analytic rules. |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊