Skip to main content

SIEM

  • July 18, 2023
  • 2 replies
  • 508 views

xavy2310
Netskope Partner
Forum|alt.badge.img+5

to restart the netskope service so that it sends the events to the Qradar Siem, what would be the command or the options?

This topic has been closed for replies.

2 replies

matt-frank
Netskope Partner
Forum|alt.badge.img+14
  • Netskope Partner
  • July 19, 2023

The easiest way to get logs from Netskope into a SIEM is using Cloud Log Shipper within Cloud Exchange.  Configure the Netskope Plugin for Log Shipper - Netskope Knowledge Portal


Forum|alt.badge.img+16
  • Netskope Employee
  • July 19, 2023

@xavy2310 do you already have Cloud Log Shipper configured?  A restart of the service should not be required unless there's an issue.  Once you've configured the plugin and sharing (business rules) then logs should begin streaming to the QRadar instance.