Netskope CASB via Cloud Exchange Syslog
Netskope tenant application events and admin audit events as delivered to a SIEM by the Cloud Exchange Log Shipper Syslog plugin v4.1.x in CEF with its default mapping, as native syslog lines in event.original with ECS and netskope.* fields. Sixty staff, six of them tenant admins, use a few cloud-storage, collaboration and CRM apps from an office or home egress address; about 4,700 events a day follow the working day in UTC. Recurring episodes show a tenant admin deleting an inline policy and then downloading a batch of files from a cloud-storage app.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/cloud-netskope-casb/generator.yml \
--id netskope \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| application / View | File or record viewed in a cloud app | 44.38% of records | file |
| application / Download | File downloaded from a cloud app | 18.32% of records | file |
| application / Login Successful | User login to a cloud app | 13.97% of records | authentication |
| application / Upload | File uploaded to a cloud-storage or collaboration app | 8.98% of records | file |
| application / Edit | File edited in a cloud-storage app | 4.11% of records | file |
| application / Join | Join activity in a collaboration app | 2.91% of records | session |
| application / Logout | User logout from a collaboration or CRM app | 1.57% of records | authentication |
| application / Share | File shared from a cloud-storage app | 1.26% of records | file |
| application / View All | View All activity in the CRM app | 1.22% of records | file |
| application / Move | File moved in a cloud-storage app | 0.99% of records | file |
| application / Rename | File renamed in a cloud-storage app | 0.74% of records | file |
| audit / Login Successful | Tenant admin logs in to the admin console | 0.62% of records | authentication |
| application / Copy | File copied in a cloud-storage app | 0.57% of records | file |
| audit / Deleted Inline Policy | Tenant admin deletes an inline policy | 0.37% of records | configuration |
Realism Features
- Sixty staff work in daily sessions from an office or home egress address, using a few cloud-storage, collaboration and CRM apps each. Most start between 07:00 and 09:30 UTC (some until 11:00, a few from 06:00) and work 6.5-10.5 h; about one in five adds a short evening session from home. Six staff form an overnight team working from about 22:00 to 07:00 UTC.
- About 4,700 events a day (day-to-day variation about 3%): 475 an hour between 10:00 and 15:00 UTC, 54 an hour overnight from a handful of users and 24 an hour between 19:00 and 23:00. Each user produces about 9 events per hour at work; about 50 users are seen per hour at midday, 6 overnight and 4-5 in the evening. The daily curve is the same every day, with no weekly cycle.
- Six staff are tenant admins who also open the admin console now and then; three of them own the inline policies and delete one on most console visits, 2-7 a day each, more than a typical tenant sees. Console logins, single and double deletions, deletions followed a few minutes later by a check of one or two files in a storage app, and bursts of many downloads by one user from one app all occur in background, but an admin who deleted a policy within the last 30 minutes makes at most two cloud-storage downloads in that window; an ordinary burst that would make a third ends at the second (about 1.5 times a day across the tenant).
- Line layout follows the plugin source: <14> priority, header time, Log Source Identifier, the CEF header with the tenant as Device Product, and extensions sorted by the key=value string. Application events carry the 14 keys of the published example plus url and appSessionId with severity Unknown; audit events carry the four published keys, High for Deleted Inline Policy and Medium for Login Successful, without supportingData.
- appSessionId stays the same for a user and app until 15 minutes of inactivity; device, OS and browser are fixed per user (Native for some sync clients). The syslog header time is the Cloud Exchange send time, assumed UTC, a random delay after the event (median about 50 s, 2 s to about 17 min); timestamp and @timestamp are the event time in whole seconds. Real batched sends are less regular, and repeated actions of one user in one app (a median 27 s apart at midday, about a minute overnight) are often only milliseconds to seconds apart in real logs.
- Only the two audit event names with published raw examples are modeled; policy creation, edits and applied changes are not. The per-app activity mix, CCI/CCL values, URLs and addresses are synthetic. With anomaly_mode true, counts of the chain parts (console logins, policy deletions, storage downloads right after a deletion) are about one per episode higher than with false.
- The default audit mapping carries no policy name or before/after state, so the chain is a temporal correlation on the actor, not proof that the deleted policy was blocking those downloads, and no restoring step is emitted. SIEM parser compatibility is untested; the ECS mapping is CEF-ingest-style enrichment, not a vendor-published mapping.
Sample Output
{
"@timestamp": "2026-09-01T14:38:10Z",
"destination": {
"ip": "192.0.2.20"
},
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "Download",
"category": [
"file"
],
"kind": "event",
"original": "\u003c14\u003eSep 01 14:39:36 netskopece CEF:0|Netskope|Example Tenant|NULL|application|NULL|Unknown|act=Download appSessionId=4396508595117720143 appcategory=Cloud Storage applicationType=nspolicy browser=Safari cci=92 ccl=excellent device=Mac Device dst=192.0.2.20 os=Sonoma requestClientApplication=Google Drive sourceServiceName=Google Drive src=198.51.100.11 suser=julia.moore@example.com timestamp=1788273490 url=drive.google.com/file/d/u197a6fe47153cd09d12e751f083",
"type": [
"access"
]
},
"log": {
"syslog": {
"hostname": "netskopece",
"priority": 14
}
},
"netskope": {
"activity": "Download",
"app": "Google Drive",
"app_session_id": "4396508595117720143",
"appcategory": "Cloud Storage",
"browser": "Safari",
"cci": "92",
"ccl": "excellent",
"device": "Mac Device",
"os": "Sonoma",
"site": "Google Drive",
"type": "nspolicy"
},
"related": {
"ip": [
"198.51.100.11",
"192.0.2.20"
],
"user": [
"julia.moore@example.com"
]
},
"source": {
"ip": "198.51.100.11"
},
"url": {
"original": "drive.google.com/file/d/u197a6fe47153cd09d12e751f083"
},
"user": {
"email": "julia.moore@example.com"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Add anomaly chain episodes; false emits background only |
| anomaly_interval_hours | 24 | Episode interval in hours of event time, 6 to 8,760 |
| tenant_name | Example Tenant | CEF Device Product (the plugin tenant name) |
| log_source_identifier | netskopece | Syslog hostname field (the plugin Log Source Identifier) |
| email_domain | example.com | Domain of user e-mail addresses in suser |
Related Generators
AWS CloudTrail Management Events
AWS CloudTrail audit trail — API calls across EC2, IAM, STS, and S3 from a multi-account organization. Includes console logins, role assumptions, error injection, and 4 identity types.
AWS GuardDuty Findings
AWS GuardDuty threat detection findings across EC2, IAM, and S3 resources. Covers 8 categories — Recon, UnauthorizedAccess, Policy, Trojan, Impact, CryptoCurrency, Stealth, and Backdoor — with 27 finding types, 10 threat actor IPs, and geo/ASN enrichment.
AWS VPC Flow Logs
AWS VPC Flow Logs (v5) — network traffic records across multiple accounts, VPCs, and subnets. TCP/UDP/ICMP flows with ACCEPT/REJECT actions, NAT gateway traffic, and realistic byte/packet distributions.