Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 

Configuring JSA to Collect Events from Your Netskope Active System

 

To collect all audit logs and system events from Netskope Active servers, you must configure JSA to collect audit logs and system events from your Netskope Active system.

The following table describes the parameters that are required to collect Netskope Active events:

Table 1: Netskope Active DSM Log Source Parameters

Parameter

Description

IP or Hostname

partners.goskope.com

Authentication Token

The authentication token is generated in the Netskope WebUI and is the only credential that is required for Netskope Active REST API usage. To access the token generation option in the Netskope WebUI, select Settings >REST API.

Automatically Acquire Server Certificates

If you choose Yes from the drop-down list, JSA automatically downloads the certificate and begins trusting the target server. The correct server must be entered in the IP or Hostname field.

Throttle

The maximum number of events per second. The default is 5000.

Recurrence

You can specify when the log source attempts to obtain data. The format is M/H/D for Months/Hours/Days. The default is 1 M.

Collection Type

All EventsSelect to collect all events.
Alerts OnlySelect to collect only alerts.
  1. Log in to JSA.
  2. Click Admin tab.
  3. In the navigation menu, click Data Sources.
  4. Click the Log Sources icon.
  5. Click Add.
  6. From the Log Source Type list, select Netskope Active.
  7. From the Protocol Configuration list, select Netskope Active REST API.
  8. Configure the parameters.
  9. Click Save.
  10. On the Admin tab, click Deploy Changes.