Netskope
Connect Netskope to Radiant Security to forward alerts and events for AI triage.
Last updated
Was this helpful?
Connect Netskope to Radiant Security to forward alerts and events for AI triage.
Netskope is a security service edge (SSE) platform that protects users and data accessing cloud services, websites, and private applications against web threats, data exfiltration, and risky cloud activity. Connecting Netskope forwards alerts and events to Radiant Security through the Netskope REST API v2. Radiant uses the alerts and events for AI triage, giving analysts cloud and web activity context alongside other security telemetry.
At the end of this configuration, you provide Radiant Security with the following values:
Tenant URL
API token
Click Add Endpoint and select the following API endpoints:
All entries that start with /api/v2/events/dataexport/events
All entries that start with /api/v2/events/dataexport/alerts
/api/v2/incidents/uba/getuci
/api/v2/incidents/dlpincidents
/api/v2/events/data/alert

Under Privilege, select Read.
Sign in to Radiant Security.
From the navigation menu, select Settings > Data Connectors and click + Add Connector.
Search for and select Netskope API v2, then click Data Feeds.
Under Select your data feeds, select Netskope API v2 and click Credentials.
Under Credential Name, enter a descriptive name (e.g., Netskope Token).
In the Tenant URL field, enter the URL you use to access the Netskope console (for example, https://companyName.goskope.com).
In the API Token field, paste the token you generated in Netskope.
Click Add Connector to save the configuration.
After Netskope begins forwarding, confirm alerts and events are reaching Radiant.
In Radiant, navigate to Log Management.
Filter by rs_connectorType:"netskope_api_v2".
Confirm recent alerts and events appear.
Allow several minutes for alerts and events to be parsed, indexed, and available for search.
Last updated
Was this helpful?
Was this helpful?