Netskope Active 샘플 이벤트 메시지

이 샘플 이벤트 메시지를 사용하여 IBM QRadar와의 성공적인 통합을 확인하십시오.

중요: IBM QRadar DSM for Netskope Active는 더 이상 사용되지 않습니다. Netskope Active REST API IBM QRadar 프로토콜은 더 이상 사용되지 않습니다.

이 통합을 계속 활용하려면 IBM Security App Exchange 웹 사이트 (https://exchange.xforce.ibmcloud.com/hub/extension/ff97aaadc10ed96b0e05d1a1f24af2f7) 에서 Netskope Security Cloud DSM을 다운로드하십시오.

Netskope Rest API 프로토콜 사용 시 Netskope Active 샘플 메시지

팁: 형식화로 인해 메시지 형식을 텍스트 편집기에 붙여넣은 후 캐리지 리턴 또는 줄 바꾸기 문자를 제거하십시오.

샘플 1: 다음 샘플 이벤트 메시지는 이상 항목 협업 이벤트를 표시합니다.

{“dstip”:”XXXXX”,”dst_location”:”XXXXX”,”last_timestamp”:1436237104,”latency_total”:74,”app”
:”Google Hangouts”,”profile_id”:”XXXX”,”last_country”:”XX”,”device”:”Windows Device”,”src_location”:”N/A”
,”alert_type”:”anomaly”,”id”:66483,”app_session_id”:XXXXX,”event_type”:”proximity”,”risk_level”:
”high”,”client_bytes”:3109,”last_location”:XXXX],”dst_region”:”XXX”,”last_device”:”Windows Device”,”conn_durat
ion”:XXX,”dst_country”:”XXX”,”resp_cnt”:3,”ccl”:”high”,”src_zipcode”:”N/A”,”req_cnt”:3,”src_timezone”:
”unknown”,”server_bytes”:2012,”type”:”connection”,”access_method”:”Client”,”latency_min”:24,
”organization_unit”:”“,”dst_latitude”:XXXX,”timestamp”:1436237457,”src_region”:”N/A”,”src_latitude”:XX,
”connection_id”:XXX,”dst_longitude”:-XXX,”alert”:”yes”,”app_action_cnt”:0,”last_app”:”Google Hangouts”,”user”
:”XXX”,”src_longitude”:-XX,”srcip”:”XXXXX”,”src_country”:”XX”,”last_region”:”CO”,”appcategory”:”Collaboration
”,”conn_endtime”:1436237457,”count”:1,”acked”:”false”,”_id”:”XXXX”,”dst_zipcode”:”XXX”,”risk
_level_id”:2,”sv”:”unknown”,”latency_max”:25,”numbytes”:5121,”alert_name”:”proximity”,”conn_
starttime”:1436237210,”userip”:”XXXX”,”telemetry_app”:”“,”browser”:”Chrome”,”os”:”Windows 8.1”}

샘플 2: 다음 샘플 이벤트 메시지는 성공적인 사용자 로그인 감사 이벤트를 표시합니다.

{“supporting_data”:{“data_values”:[“XXX”,”XXXX],”data_type”:”user”},”severity_level”:2,”time
stamp”:1419922155,”organization_unit”:”“,”ccl”:”unknown”,”user”:”XXXXXX”,”audit_log_event”:”Login Succes
sful”,”_id”:”XXXXXX”,”type”:”admin_audit_logs”,”appcategory”:”n/a”}