Skip to main content

Hello Folks, 

Below you can find a recap of the topics discussed during the September Advanced Analytics office hours and those sent in that we were not able to cover in the session. Feel free to comment and continue the discussion, as well as attend our future sessions that can be found from the Community Events Calendar!

 

Q: Are there any recommended dashboards for security operations monitoring?

A: There are 3 different “health check” dashboards in our community. All of them are great starting points for you to monitor security operations.

 

CASB Health Check Dashboard

The purpose of this dashboard is to help you maximize the ROI of your Netskope investment and to ensure you are using Netskope products to their full potential. With a focus on CASB, the dashboard covers multiple topics such as NewEdge Network, Traffic Steering, SSL Inspection, Application Risk Management, Malware Protection, and DLP, which answers the question “how Netskope is protecting your environment.” Recommendations / call to actions / best practices are provided in each section, which helps you better understand how to mitigate the security concerns identified & enhance your security posture correspondingly. 

AD_4nXcma21g926hBBs98r9id2q1ZwLSJ3qkarNMm8wl4S7rcQ2H7yBDVmRxCGFiuMOtozoHK0Oca3QzxyrKAUP8gddTAKiOq9LwpRNx4KZTY79jEO5vEtXombkuz2LQXVU_sNXFjS0oFXTIkb8iRIeiwav0TOc?key=NJAoyVjdbgiAYFc2ujtw0g

A typical use case with this dashboard is “to highlight change and demonstrate value.” For example, if you enhanced your threat protection by tuning your malware block policies and now want to see if the policies were working effectively in the past few months, the Inline Malware Blocks section of this dashboard will be a great option. It shows how the “blocked malware count” was changing over time, which highlights the value of the enhancement you have made to threat protection. 

AD_4nXfi3qfmvVs9CTSac_cZkvbIEfDV-E1CfsWHU343b7Ixb2kbCgwxMLh7ziVJjr5C1Qjly3xBdTM4-FMXlWoYgaLsYrq5qkxuIpF0U8-VeMU1jreURcSEUn0-ywR5QFPsg0b8188LpQ?key=NJAoyVjdbgiAYFc2ujtw0g

 

NG-SWG Health Check Dashboard

This dashboard shares the same purpose and use cases with the CASB Health Check Dashboard above, but focuses on NG-SWG. 

 

Security Health Check (Self-Service) Dashboard

This is an all-in-one dashboard which allows you to perform self-service health checks and to identify security concerns / issues in your environment. The dashboard answers 2 questions: 1) How Netskope is protecting your environment; 2) What Netskope is protecting your environment from. 

Compared to the previous CASB and NG-SWG Health Check Dashboards that focus on showcasing business values, this dashboard focuses on quickly locating security concerns / issues in your environment. 

More topics such as Device & Client Management, Alerts, and Policies are covered in this dashboard, which provides a high-level overview of your entire environment. 

AD_4nXe-_QCxXiQ2EjU6K4oHbiU5rWAUStQMybrR6blDTBpd6nxCWFgpu5AdEY287sGU-RbRxV-ws9LYW8neJ_SyT9eCDL7_BXcYq0KXGaPvWZrZIcZe-6ozdzdGnrWS3TYRum8QIdJF0bWLXgHmdfYY832T-xU?key=NJAoyVjdbgiAYFc2ujtw0g

“User investigation” tables are also included, which helps you source all the risky traffic in your environment. 

AD_4nXf18DjqQ-3Z1XZ_wiLBX7Q1aPnreUm3fcLZKf0kbvV_kvD5gpLfbzfhn0tIqJzVrYtMbaltq7xQgL3jF6wqvUUBtCIXjqavdkp7_9I78q6N8zkzjoM32ooZDk_9MQGNweUEwhc9n5drZJgNwblmJvHGKAzk?key=NJAoyVjdbgiAYFc2ujtw0g

A typical use case with this dashboard is “threat hunting / troubleshooting.” If you observe some unexpected / anomalous data (e.g. an extremely high number of DLP alerts triggered in the past 7 days) and want to understand why this is happening, this dashboard is a great option. You can also leverage this dashboard to perform regular health checks to your environment.

 

Q: How does Advanced Analytics help monitor AI usage?

A: The AI Usage Dashboard in Netskope Library allows you to monitor AI usage from the big picture. The data provided helps you identify trends/patterns of AI usage such as AI app usage trend, user group breakdown, activity summary, instance awareness, and policy action. 

AD_4nXcysdvUzNvylsSKpXAzA5aqqe8cD2qibQE5iREjsA3u7NOaWDno_Il58yBD4fFTPwbvHG_h2w5vD3yftVx4Ga835ljQ1VGfOFFIBdHrPYncG_LYPfHRExWlhxvD_1hiIZZtdEP_?key=NJAoyVjdbgiAYFc2ujtw0g

Another great dashboard is the DeepSeek Usage Dashboard that provides detailed visibility into how DeepSeek is being used in your environment. The dashboard helps you identify suspicious/risky user activities such as sensitive data movement, unexpected justification reasons, and anomalous web transactions.

AD_4nXc_m2ZU4KGAOxKZXLHqVHlBDxVNYH-Da_HFTch_8ZFe_slWi8l7SDMiJRDWjWcUx3e3QUMV3C8jI7B_48DqJOi0Hd5trDK6eOSG3cl9Y20YWmvxfb-6reUsikAfn3GVRwjsUH7lrQ?key=NJAoyVjdbgiAYFc2ujtw0g

Of course, based on your use cases, you can update this dashboard with a focus on any other AI apps. The only thing you need to do is change the “Application” filter on top of the dashboard.

AD_4nXdIvmQoHGAws-9q5KR-m6rE9slvlqC6UjyE_hz8YA7xyXuJDI8l3305zqOpyOxuzGeGiPbRlhis5MrsIrCfofOm4rrGochM9MeUg0z9koffeoc1vG8xII-YNn5glvRwpwGol04I?key=NJAoyVjdbgiAYFc2ujtw0g

 

Q: What are the recommended dashboards that can be used to monitor risky user behaviors?

A: The User Behavior Analytics (UBA) Dashboard is a good starting point. The dashboard helps you monitor anomalous user behaviors in your environment by providing high-level overviews of the UBA alerts triggered and detailed visibility into each type of UBA alerts.

If you are looking to drill into user activities, the User/Organization Unit Investigation Dashboard in our community will be a great option. This dashboard provides both high-level and detailed visibility into user activities, which helps you identify and monitor suspicious/risky user activities, e.g. PCI files uploaded through non-corporate instances, in your environment.  

 

Q: How to use Advanced Analytics to protect our organization from Shadow IT?

A: The Application Risk Management Dashboard is a great starting point to uncover risky app usage. The dashboard helps you better understand:

  • What risky & unmanaged apps are being used in your environment
  • If there is any sensitive data movement to these risky & unmanaged apps
  • If there are any non-corporate app instances in use and the corresponding user activities

 

Q: How to use custom fields to address advanced use cases?

A: There are 3 types of custom fields in Advanced Analytics: Custom Dimension, Custom Measure, & Table Calculation. Based on the real-world scenarios, this post in our community showcases how to best use custom fields to address advanced use cases with step by step instructions. Take a look!

 

Q: What training documentation is accessible for us to develop foundational knowledge to execute Netskope for security posture?

A: There are 3 recommended resources:

Netskope Learning Path

This is the primary starting point for you to develop foundational knowledge of Netskope products and learn about best practices.

Netskope Academy / Training Discussions

This is the place for you to level up your Netskope product knowledge, view the latest training resources, connect with your peers, and provide feedback.

Inside Netskope

This is the place for you to understand how Netskope is leveraging Netskope products to address Netskope’s own use cases.

 

Q: Does Advanced Analytics provide visibility into web traffic or bandwidth usage in our organization?

A: Yes, our latest Bandwidth Consumption Dashboard can help you monitor bandwidth usage in your environment based on 3 trending use cases:

  • Uncover malicious/suspicious sites with high bandwidth usage
  • Monitor bandwidth usage by geolocation; avoid overusing your license in particular regions
  • Monitor bandwidth usage by office locations; consider upgrading/adding internet circuits

AD_4nXc2GcGrzFXUwwcvgbQx1CNogFtoqfZUKfM-3zM90vOzqu6SFklCb7qFkAvhcVXIj58t_jAqB0tmzc2I_Vtfrr7cZFwehA2ngnpumb33cnssrkLydVc46K7DgFwufLZFlaI4N7Ag?key=NJAoyVjdbgiAYFc2ujtw0g

Looking to better investigate bandwidth issues? Digital Experience Management (DEM) can help. Learn more about Netskope One DEM.

 

Resource shared in the session:

Netskope Community - Advanced Analytics: https://community.netskope.com/p/advanced-analytics 

Training Resources Post: https://community.netskope.com/dashboard-gallery-38/advanced-analytics-training-resources-5713?tid=5713&fid=38 

Copy Existing Widgets:

https://community.netskope.com/discussions-37/copy-widgets-from-existing-dashboards-to-your-own-dashboards-7655 

AI Usage Dashboard Demo:

https://community.netskope.com/video-library-20/netskope-advanced-analytics-ai-usage-dashboard-demo-6924 

DeepSeek Usage Dashboard:

https://community.netskope.com/dashboard-gallery-38/deepseek-usage-dashboard-7385 

User/Organization Unit Investigation Dashboard:

https://community.netskope.com/dashboard-gallery-38/user-organization-unit-investigation-dashboard-7349 

Application Risk Management Dashboard:

https://community.netskope.com/dashboard-gallery-38/application-risk-management-6132 

Application Instance Overview Dashboard:

https://community.netskope.com/dashboard-gallery-38/manage-your-application-instances-through-instance-tags-7928 

CASB Health Check Dashboard V2.7:

https://community.netskope.com/dashboard-gallery-38/casb-health-check-dashboard-6075 

NG-SWG Health Check Dashboard V2.8:

https://community.netskope.com/dashboard-gallery-38/ng-swg-health-check-dashboard-6104

Netskope Learning Path:

https://community.netskope.com/p/netskopecustomerworkshops 

Netskope Academy / Training Discussions:

https://community.netskope.com/netskope-academy-training-discussions-19

Inside Netskope: https://community.netskope.com/inside-netskope-22 

 

Be the first to reply!

Reply