Currently, when reviewing Admin Audit Logs in the Netskope tenant, events recording that an administrator disabled or altered a Netskope Client state do not indicate which specific user, endpoint, host, or tenant device was affected.
The audit log captures who (the performing admin) initiated an action, but omits the target entity (the impacted user or machine). We request that Netskope enhance Admin Audit Logs to capture the target user identity (UPN/email), device name/hostname, and client ID directly in the event details and log payload.
Problem & Impact
-
Security & Compliance Gap:
-
Lack of Accountability: Reviewers and SOC analysts cannot determine whether a client disable was an authorized support action or unauthorized administrative tampering.
-
Audit Blindspot: Internal and external compliance audits require full attribution (Subject, Action, Target/Object). Without target details, client disablement events cannot satisfy traceability standards.
-
-
Operational & Troubleshooting Friction:
-
Incident Investigation Delays: When an end user reports an inactive or disabled Netskope client, support engineers cannot correlate the client state with admin activity logs unless they cross-reference external helpdesk tickets.
-
SIEM / SIEM Forwarder Limitation: When Admin Audit Logs are ingested into SIEM/XDR platforms (e.g., via Netskope Cloud Exchange / Log Streaming), SOC teams cannot write detection rules for high-risk behavior (e.g., targeted disablement of executive devices or bulk disables).
-
Proposed Enhancement
-
Log Payload Enrichment: Include the following metadata attributes within the Admin Audit Log event for client disable/tamper-related actions:
-
Target User(UPN / Email) -
Target Hostname / Device Name -
Client ID / Device ID -
Client Version & OS -
Reason / Justification(if a prompt is enabled for disablement)
-
-
UI Visibility: Add dedicated columns or expandable detail drawers under Settings > Administration > Audit Log to view target entities without needing raw JSON parsing.
-
API / Cloud Exchange Support: Ensure these fields are exposed via the v2 Admin Audit API and Cloud Exchange Log Streamer.
Use Case Example
-
Scenario: An incident responder notices an admin account disabled client protection.
-
Current Outcome: The log only shows:
Admin: admin@company.com performed action: Client Disable. The responder must manually check multiple endpoint tables or contact the admin to find out which host was modified. -
Desired Outcome: The log shows:
Admin: admin@company.com disabled client for Target User: user@company.com on Host: LAPTOP-X1234 (Client ID: 98765)



