SIEM

  • 18 July 2023
  • 2 replies
  • 79 views

Userlevel 1
Badge +5

to restart the netskope service so that it sends the events to the Qradar Siem, what would be the command or the options?


2 replies

Userlevel 3
Badge +14

The easiest way to get logs from Netskope into a SIEM is using Cloud Log Shipper within Cloud Exchange.  Configure the Netskope Plugin for Log Shipper - Netskope Knowledge Portal

Userlevel 6
Badge +16

@xavy2310 do you already have Cloud Log Shipper configured?  A restart of the service should not be required unless there's an issue.  Once you've configured the plugin and sharing (business rules) then logs should begin streaming to the QRadar instance. 

Reply