All Apps and Add-ons

Mapping of event fields between Netskope Add-on for Splunk and Splunk

ShadowMachhi
New Member

Hi,

Kindly advise on the mapping that is made in Splunk for events between the Netskope Add-on For Splunk TA.

Based on Netskope docs (Transaction Event Fields - Netskope Knowledge Portal)

x-policy-name appears to be the netskope field for the RTP web policy and
x-ssl-policy-name looks like the Name of the SSL Decryption Policy that matched the request.

I need to make sure the Netskope TA in splunk is not mapping them BOTH to the POLICY field in Splunk.

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @ShadowMachhi 

There doesnt seem to be a field eval/alias to 'policy' in the Netskope Add-on for Splunk app.

The only thing I can see is in the 'netskope:application' sourcetype which is aliasing 'policy' to 'signature' .

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...