Hi Team,
I do not believe "Fallback Action" is available as a standalone filter in Netskope reporting/search. Based on Netskope documentation, a fallback action is triggered when the content inspection engine cannot complete analysis (for example, file size limit exceeded, scan timeout, or internal scanning error), and the system applies the configured fallback action (Allow/Alert/Block).
If the goal is to determine how many fallback actions occurred historically, we may need to look for the resulting events/actions rather than filter directly on "Fallback Action." I have not found evidence that Netskope provides a dedicated Fallback Action filter in the UI.
As an alternative, it may be possible to identify these events through SkopeIT/Event exports or log analysis by looking for scan failures, timeout conditions, file size limit exceedances, or other fallback-related indicators if those fields are logged in our environment.
Has anyone identified a field in SkopeIT, Reporting, or exported logs that explicitly records when a fallback action was invoked?



