Hi,
Kindly advise on the mapping that is made in Splunk for events between the Netskope Add-on For Splunk TA.
Based on Netskope docs (Transaction Event Fields - Netskope Knowledge Portal)
x-policy-name appears to be the netskope field for the RTP web policy and
x-ssl-policy-name looks like the Name of the SSL Decryption Policy that matched the request.
I need to make sure the Netskope TA in splunk is not mapping them BOTH to the POLICY field in Splunk.
There doesnt seem to be a field eval/alias to 'policy' in the Netskope Add-on for Splunk app.
The only thing I can see is in the 'netskope:application' sourcetype which is aliasing 'policy' to 'signature' .
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing