Skip to main content
Sumo Logic

Install the Netskope App and view the Dashboards

This page demonstrates how to install the Netskope App, and provides examples and descriptions for each of the dashboards.

This page demonstrates how to install the Netskope App, and provides examples and descriptions for each of the dashboards. The Netskope App has the following components:

  • Application Usage: Insights into application usage; specifically by devices, users, users and traffic patterns.
  • Security Alerts: Visibility into Netskope security alerts and violations and the ability to identify effects of a breach.  

Install the App

This section provides instructions for installing the Netskope App.

To install the Netskope App, do the following:

Locate and install the app you need from the App Catalog. If you want to see a preview of the dashboards included with the app before installing, click Preview Dashboards.

  1. From the App Catalog, search for and select the app. 
  2. To install the app, click Add to Library and complete the following fields.
    1. App Name. You can retain the existing name, or enter a name of your choice for the app.

    2. Data Source. Select either of these options for the data source.

      • Choose Source Category, and select a source category from the list.

      • Choose Enter a Custom Data Filter, and enter a custom source category beginning with an underscore. Example: (_sourceCategory=MyCategory).

    3. Advanced. Select the Location in Library (the default is the Personal folder in the library), or click New Folder to add a new folder.
    4. Click Add to Library.

Once an app is installed, it will appear in your Personal folder, or other folder that you specified. From here, you can share it with your organization. 

Panels will start to fill automatically. It's important to note that each panel slowly fills with data matching the time range query and received since the panel was created. Results won't immediately be available, but with a bit of time, you'll see full graphs and maps. 

Dashboard filters

Each dashboard has a set of filters that you can apply to the entire dashboard, as shown in the following example. Click the funnel icon in the top dashboard menu bar to display a scrollable list of filters that are applied across the entire dashboard.

Netskope_Dashboard-filter.png

Each panel has a set of filters that are applied to the results for that panel only, as shown in the following example. Click the funnel icon in the top panel menu bar to display a list of panel-specific filters.

Netskope_Panel-filter.png

Dashboard Categories

The Netskope dashboards are grouped by their component in the following two category folders:

  • Application Usage
  • Security Alerts

Netskope - Application Overview Dashboard

Netskope - Application Overview Dashboard provides a high-level view of user activity, user geographic location by source IP, total sessions, applications used, distribution and activity of applications, and application trends over time.

Use this dashboard to:

  • Monitor number of users, sessions, and sites using the applications, and find out the popular apps by user and app category.
  • Track spikes in application usage over time.

 Netskope_Application_Overview.png

Netskope - Application Users Dashboard

Netskope - Application Users Dashboard provides a high-level view of application events, total sessions, user activity and geographic location by source IP and destination IP. This dashboard also shows visual breakdowns of distributions by operating system, browser, device, and user activity.

Use this dashboard to:

  • Monitor recent user activities, track user locations, and find out the top users affected by alerts.
  • Determine user classifications by browsers, devices, operating system (OS).

Netskope_Application_Users.png 

Netskope - Application Details Dashboard

Netskope - Application Details Dashboard provides a high-level view of data for unique applications used, as well as top applications by alerts, bytes, and average page duration. This dashboard also provides a visual breakdown of applications by category, devices by user access, and network usage over time.

Use this dashboard to:

  • Monitor the top applications generating alerts.
  • Find out detailed information about application usage in terms of  page duration, user counts, upload and download bytes.

 

Netskope_Application_Detail.png

Netskope - Alert Overview Dashboard

Netskope - Alert Overview Dashboard provides a high-level view of your alert data by type, geographic location of source IPs, total and top alerts, alerts by user, recent alerts, and alert trends over time.

Use this dashboard to:

  • Track users affected by alerts.
  • Monitor abnormal spikes, alert locations, and recent alerts.

Netskope_Alert_Overview.png

Netskope - Alert Details Dashboard

Netskope - Alert Details Dashboard provides a visual presentation of alert analytics, including the geographic locations of suspicious source and destination IPs, a time compare of alters, alert outlier trends over time, alerts by application, and recent alerts with a poor cloud confidence level.

Use this dashboard to:

  • Compare alerts over time and anomalies in alert rates.
  • Track which applications are producing the most alerts over time.

Netskope_Alert_Details.png

Netskope - Data Loss Prevention Dashboard

Netskope - Data Loss Prevention Dashboard provides a high-level view of data loss prevention (DLP) analytics, including incidents by policy over time, incidents by severity and application, incidents by operating system (OS) and browser. This dashboard also shows data on DLP rules, top profiles, incident count, and users affected.

 Use this dashboard to:

  • Track users and applications affected by DLP incidents.
  • Monitor High Severity DLP incidents.
  • Determine objects with critical severity.

Netskope_Data_Loss_Prevention.png 

Netskope - Compromised Credentials Dashboard

Netskope - Compromised Credentials Dashboard provides easily accessible analytics on compromised credentials, including the number of users with compromised credentials, a breach count and top breaches, and source info. This dashboard also provides data on recent compromised credentials, apps used by users after a credentials breach, and user activities after a credentials breach.

Use this dashboard to:

  • Track credential breaches along with their source.
  • Monitor user activities.
  • Monitor application usage after credentials have been breached.

 Netskope_Compromised_Credentials.png

Netskope - Malware Dashboard

Netskope - Malware Dashboard provides a high-level view of total malwares detected, total apps and users affected, total files infected, top source IPs and malware types, and the top users affected. This dashboard also provides data malware incidents by app and severity, affected file types, apps used on infected machines, and the user activity on infected machines.

Use this dashboard to:

  • Determine applications and users affected by malware.
  • Monitor user activity on affected machines.

Netskope_Malware.png

Netskope - Anomalies Dashboard

Netskope - Anomalies Dashboard provides an at-a-glance view of anomalies on your environment, including the number of anomalies, users affected, anomalies over time, anomalies by app, alert name, and risk level. It also includes data on top users by anomaly risk level and recent anomalies by high risk level.

Use this dashboard to:

  • Monitor anomalies in users activities.
  • Track anomalies with high risk levels.

Netskope_Anomalies.png