forked from demisto/content
-
Notifications
You must be signed in to change notification settings - Fork 13
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Netskope event collector rewrite (demisto#28941)
* Temporarily added the following packs to the update_core_packs_list: Core, DemistoRESTAPI, FiltersAndTransformers, Palo_Alto_Networks_WildFire, rasterize * Added all packs to update core list * Added al core packs to update_core_packs_list * Added new API endpoint * Added testing copies * changes from testing * changes from testing * changes from testing * Changed default first fecth * Added slipping for no wait time * First code change * Fixed description and log * UT fixes + mypy * UT fixes + mypy * Bumped Docker image and added rn * Formatting and typos * Fixed honor_rate_limit and added ut * Flake 8 fix * Added more UT * revert core list change * Enhanced docs * Small UT fixes * Removed is_command variable * Added docs Fixed UT * changes rn version * - Removed first_fetch param - Added types to perform_data_export parameters - Removed unused code * lint fixes * lint fixes
- Loading branch information
1 parent
2d9d537
commit 6a1e527
Showing
12 changed files
with
2,083 additions
and
617 deletions.
There are no files selected for viewing
431 changes: 239 additions & 192 deletions
431
Packs/Netskope/Integrations/NetskopeEventCollector/NetskopeEventCollector.py
Large diffs are not rendered by default.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
15 changes: 9 additions & 6 deletions
15
...skope/Integrations/NetskopeEventCollector/NetskopeEventCollector_description.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,15 +1,18 @@ | ||
### Netskope Event Collector | ||
## Netskope Event Collector | ||
|
||
### General Info | ||
- Collects events extracted from SaaS traffic and logs. | ||
- The collector collects 5 types of events: | ||
- Audit | ||
- Application | ||
- Network | ||
- Alert | ||
- Page | ||
- To generate the API token, in your Netskope UI go to **Settings** > **Tools** > **Rest API v1 or v2** | ||
- Please make sure to choose the appropriate **API token** according to the chosen **API Version**. | ||
- Visit the [Netskope API Overview](https://docs.netskope.com/en/rest-api-v2-overview-312207.html) for more information. | ||
|
||
|
||
- Note: The collector can handle 10K events per minute on average per each event type. | ||
|
||
### API Key | ||
- To generate the API token, in your Netskope UI go to **Settings** > **Tools** > **Rest API v2** | ||
- The KEY requires the following permissions: | ||
- /api/v2/events/dataexport/events/* | ||
- /api/v2/events/dataexport/alerts/* | ||
- Visit the [Netskope API Overview](https://docs.netskope.com/en/rest-api-v2-overview-312207.html) for more information. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
File renamed without changes.
File renamed without changes.
Oops, something went wrong.