--- id: netskope-webtx-streaming title: Netskope WebTx Streaming sidebar_label: Netskope WebTx Streaming description: The Sumo Logic app for Netskope WebTx Streaming collects transaction events from the Netskope platform to enhance visibility into your web transactions. slug: /help/docs/integrations/saas-cloud/netskope-webtx-streaming/ canonical: https://www.sumologic.com/help/docs/integrations/saas-cloud/netskope-webtx-streaming/ --- import useBaseUrl from '@docusaurus/useBaseUrl'; Netskope WebTx icon The Sumo Logic app for Netskope WebTx Streaming provides real-time visibility into web transaction data streamed from the Netskope platform, helping organizations monitor and secure their cloud and web traffic. The app includes five purpose-built dashboards covering transaction health, security posture, file activity, network insights, and user and application behavior. Security and IT teams can detect policy violations, track data movement, identify risky activity, and manage application governance from a single unified view. :::info This app includes [built-in monitors](#netskope-webtx-streaming-alerts). For details on creating custom monitors, refer to [Create monitors for Netskope WebTx Streaming app](#create-monitors-for-netskope-webtx-streaming-app). ::: ## Sample log message ```json title="Web Transaction Logs" date,time,time-taken,cs-bytes,sc-bytes,bytes,c-ip,s-ip,cs-username,cs-method,cs-uri-scheme,cs-uri-query,cs-user-agent,cs-content-type,sc-status,sc-content-type,cs-dns,cs-host,cs-uri,cs-uri-port,cs-referer,x-cs-session-id,x-cs-access-method,x-cs-app,x-s-country,x-s-latitude,x-s-longitude,x-s-location,x-s-region,x-s-zipcode,x-c-country,x-c-latitude,x-c-longitude,x-c-location,x-c-region,x-c-zipcode,x-c-os,x-c-browser,x-c-browser-version,x-c-device,x-cs-site,x-cs-timestamp,x-cs-page-id,x-cs-userip,x-cs-traffic-type,x-cs-tunnel-id,x-category,x-other-category,x-type,x-server-ssl-err,x-client-ssl-err,x-transaction-id,x-request-id,x-cs-sni,x-cs-domain-fronted-sni,x-category-id,x-other-category-id,x-sr-headers-name,x-sr-headers-value,x-cs-ssl-ja3,x-sr-ssl-ja3s,x-ssl-bypass,x-ssl-bypass-reason,x-r-cert-subject-cn,x-r-cert-issuer-cn,x-r-cert-startdate,x-r-cert-enddate,x-r-cert-valid,x-r-cert-expired,x-r-cert-untrusted-root,x-r-cert-incomplete-chain,x-r-cert-self-signed,x-r-cert-revoked,x-r-cert-revocation-check,x-r-cert-mismatch,x-cs-ssl-fronting-error,x-cs-ssl-handshake-error,x-sr-ssl-handshake-error,x-sr-ssl-client-certificate-error,x-sr-ssl-malformed-ssl,x-s-custom-signing-ca-error,x-cs-ssl-engine-action,x-cs-ssl-engine-action-reason,x-sr-ssl-engine-action,x-sr-ssl-engine-action-reason,x-ssl-policy-src-ip,x-ssl-policy-dst-ip,x-ssl-policy-dst-host,x-ssl-policy-dst-host-source,x-ssl-policy-categories,x-ssl-policy-action,x-ssl-policy-name,x-cs-ssl-version,x-cs-ssl-cipher,x-sr-ssl-version,x-sr-ssl-cipher,x-cs-src-ip-egress,x-s-dp-name,x-cs-src-ip,x-cs-src-port,x-cs-dst-ip,x-cs-dst-port,x-sr-src-ip,x-sr-src-port,x-sr-dst-ip,x-sr-dst-port,x-cs-ip-connect-xff,x-cs-ip-xff,x-cs-connect-host,x-cs-connect-port,x-cs-connect-user-agent,x-cs-url,x-cs-uri-path,x-cs-http-version,rs-status,x-cs-app-category,x-cs-app-cci,x-cs-app-ccl,x-cs-app-tags,x-cs-app-suite,x-cs-app-instance-id,x-cs-app-instance-name,x-cs-app-instance-tag,x-cs-app-activity,x-cs-app-from-user,x-cs-app-to-user,x-cs-app-object-type,x-cs-app-object-name,x-cs-app-object-id,x-rs-file-type,x-rs-file-category,x-rs-file-language,x-rs-file-size,x-rs-file-md5,x-rs-file-sha256,x-error,x-c-local-time,x-policy-action,x-policy-name,x-policy-src-ip,x-policy-dst-ip,x-policy-dst-host,x-policy-dst-host-source,x-policy-justification-type,x-policy-justification-reason,x-sc-notification-name,sr-bytes,rs-bytes,x-action,x-action-reason,x-c-authn-user,x-c-authn-source,x-c-authn-surrogate,x-c-authn-surrogate-status,x-c-authz-groups,x-c-authz-ou,x-cs-xau,x-cs-connect-xau,x-c-user-confidence-index,x-c-hostname,x-c-device-uid,x-c-os-family,x-c-os-version,x-c-nsclient-version,x-c-nsclient-client-profile,x-c-nsclient-steering-profile,x-c-device-classification,x-cs-nsclient-tunnel-type,x-cs-process,x-cs-pid,x-cs-parent-process,x-cs-ppid,x-tp-result,x-tp-engine,x-tp-malware-name,x-tp-severity,x-sr-forward-dest,x-ssl-policy-issuer,x-eip-policy-name,x-eip-policy-footprint,x-policy-categories,x-c-timezone,x-support,x-r-country,x-r-latitude,x-r-longitude,x-r-location,x-r-region,x-r-zipcode,x-c-authz-source,x-cs-app-instance-tags,x-cs-ssl-malformed-ssl,x-cs-access-proxy,x-c-local-timestamp,x-r-cert-start,x-r-cert-end,x-tenant-id 2026-07-22,15:36:01,203,1136,338,1474,79.132.139.199,79.132.139.199,draval@evwwgvlmpf.net,PUT,https,a=1784727361&sa=1&v=1.281.0,Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML like Gecko) Chrome/119.0.0.0 Safari/537.36,application/xml,404,application/json,gumi-cryptos.video-meeting.team,gumi-cryptos.video-meeting.team,/events/log,443,https://gumi-cryptos.video-meeting.team/,1669288500000137208,Client,LinkedIn,US,37.7147,-121.9300,San Francisco,California,94103,MX,40.7809,-73.9502,New York,New York,10028,Mac OS,Chrome,119,Mac Device,google,1784727361,1669288500000331711,79.132.139.199,Web,998a4499-a5a6-4a55-b243-b67ce89dd870,Consumer,Cloud Storage; Content Server; Grouping of ALL Categories for DLP,http_transaction,,,178472736125640409,1669288500000091008,google.com,,7,7; 547; 10004,,,3d908070f157946cc4ea9dca39dbe374,907bf3ecef1c987c889946b737b43de8,no,,*.google.com,GTS CA 1C3,Jul 22 15:36:01 2026 GMT,Jul 22 15:36:01 2026 GMT,yes,no,no,no,no,no,OCSP,no,no,no,no,no,no,no,allow,SSL negotiation successful,allow,Valid certificate,79.132.139.199,79.132.139.199,gumi-cryptos.video-meeting.team,Sni,Cloud Storage,Decrypt,Default Decrypt,TLSv1.3,TLS_AES_256_GCM_SHA384,TLSv1.3,TLS_AES_256_GCM_SHA384,79.132.139.199,US-SJC1,79.132.139.199,54447,79.132.139.199,443,79.132.139.199,15556,79.132.139.199,443,79.132.139.199,79.132.139.199,gumi-cryptos.video-meeting.team,443,Mozilla/5.0 (Windows NT 10.0; WOW64; rv:50.0) Gecko/20100101 Firefox/50.0,https://gumi-cryptos.video-meeting.team/log?format=json&hasfast=true&authuser=0,/log,HTTP/2,200,Cloud Storage,91,excellent,sanctioned,Google,1iNtlIbpIivrmMEHPgtjEDk_T5Fe0a778,company-google,sanctioned,Approve,user@company.com,user@partner.com,File,sample-data.pdf,file_12345,application/json,Text,en,2048,bcdd51c6a4f3f99c4e658f07e4c57e91,9d3ee36999244e46f70b11d241a8d10c5bbbc758d5b5654681aa18e1137a4a87,,Jul 22 15:36:01 2026 GMT,allow,DefaultAction,79.132.139.199,79.132.139.199,gumi-cryptos.video-meeting.team,Sni,,,,1024,2048,Allow,,bobbuilder@netskope.com,NSClient-Tunnel,Tunnel,Authenticated,engineering; sales,Corp/US/Engineering,,,950,C02GH1DMMD6N,BC5A83EE-5FF1-6F51-FDD1-84CAFBF60E9E,macOS,14.3.1,114.0.0.2012,Default Profile,Prd_Steering_Config-A,managed,TLS,chrome.exe,4704,explorer.exe,1,clean,BitDefender,,low,,Netskope CA,Default Egress,ABC,Cloud Storage; Content Server,-05:00,1-2:3:4,US,37.4192,-122.0574,Mountain View,California,94043,saml,sanctioned; corporate,no,ap-default,1784727361,1784727361,1784727361,324123 ``` ## Sample queries ```sumo title="Total Transactions" _sourceCategory="Labs/NetskopeWebTxStreaming" !bytes | csv _raw extract 14 as cs_content_type, 17 as cs_dns, 10 as cs_method, 9 as cs_username, 15 as sc_status, 37 as x_c_os, 47 as x_category, 24 as x_cs_app, 45 as x_cs_traffic_type, 49 as x_type, 52 as x_transaction_id ///global filters | where if ("{{cs_content_type}}" = "*", true, cs_content_type matches "{{cs_content_type}}") | where if ("{{cs_dns}}" = "*", true, cs_dns matches "{{cs_dns}}") | where if ("{{cs_method}}" = "*", true, cs_method matches "{{cs_method}}") | where if ("{{cs_username}}" = "*", true, cs_username matches "{{cs_username}}") | where if ("{{sc_status}}" = "*", true, sc_status matches "{{sc_status}}") | where if ("{{x_c_os}}" = "*", true, x_c_os matches "{{x_c_os}}") | where if ("{{x_category}}" = "*", true, x_category matches "{{x_category}}") | where if ("{{x_cs_app}}" = "*", true, x_cs_app matches "{{x_cs_app}}") | where if ("{{x_cs_traffic_type}}" = "*", true, x_cs_traffic_type matches "{{x_cs_traffic_type}}") | where if ("{{x_type}}" = "*", true, x_type matches "{{x_type}}") // panel specific | count by x_transaction_id | count ``` ## Collecting logs This section has instructions for collecting logs for the Sumo Logic app for Netskope WebTx Streaming. ### Collection process overview The Sumo Logic app for Netskope WebTx Streaming ingests transaction logs that Netskope delivers to an Amazon S3 bucket through Log Streaming. At a high level, you'll: 1. In Netskope, set up [Log Streaming](https://docs.netskope.com/en/log-streaming) to forward transaction logs to an Amazon S3 bucket. 2. In Sumo Logic, create an [AWS S3 Source](/docs/send-data/hosted-collectors/amazon-aws/aws-s3-source/) that reads from the same bucket. 3. Install the app and point it to the source category assigned to that S3 source. If Netskope transaction logs are already flowing into Sumo Logic through an existing S3 source, you can skip creating a new source. Just make a note of its source category and use it when you install the app. When you configure the transaction log stream in Netskope, make sure the following settings match what the app expects: - **Log format**. The app supports the CSV log format defined in the [Netskope event schema](https://github.com/netskopeoss/Data-Schema/blob/main/schema/event_schema.json) and reads fields based on their `position` values. This corresponds to the **Parser order 2** format for transaction events in Log Streaming, so make sure to select Parser order 2 when configuring the transaction log stream. - **Delimiter**. Use the comma (`,`) delimiter when configuring transaction logs in Log Streaming. The app expects comma-separated values for parsing the log data correctly. ## Installing the Netskope WebTx Streaming app This section shows you how to install the Sumo Logic app for Netskope WebTx Streaming. import AppInstall2 from '../../reuse/apps/app-install-v2.md'; ## Viewing the Netskope WebTx Streaming dashboards​​ import ViewDashboards from '../../reuse/apps/view-dashboards.md'; ### Overview The **Netskope WebTx Streaming - Overview** dashboard in Sumo Logic provides a high-level view of web transaction activity, covering total transactions, HTTP and WebSocket volumes, and average response times. It includes geographic maps for client and server locations along with breakdowns by HTTP status, cloud applications, and web categories. Transaction trends over time and a recent transactions table give teams a single-pane view for operational monitoring and performance management. Netskope WebTx Streaming Overview ### Security Overview The **Netskope WebTx Streaming - Security Overview** dashboard in Sumo Logic delivers a focused view of web transaction security for network administrators and security teams. It highlights blocked transactions, triggered policies, unauthorized access attempts, and SSL errors, while surfacing risky geographic activity and potential data exfiltration. Upload and download trends provide additional context for data movement, making this dashboard essential for threat detection and compliance monitoring. Netskope WebTx Streaming Security Overview ### File Activity The **Netskope WebTx Streaming - File Activity** dashboard in Sumo Logic tracks file transfer activity across web transactions. It provides visibility into object type distributions, top file types transferred, and data throughput trends over time. A detailed recent file transfer events table captures object names, types, categories, and sizes, helping teams monitor data movement and support data loss prevention efforts. Netskope WebTx Streaming File Activity ### Client and Network Insights The **Netskope WebTx Streaming - Client and Network Insights** dashboard in Sumo Logic offers visibility into the network and client-side aspects of web transactions. It covers top DNS destinations, transaction hosts, geographic regions, HTTP methods, operating systems, browser types, device types, and access methods. These insights give network and IT teams the context needed to understand client diversity, traffic patterns, and access behaviors across the environment. Netskope WebTx Streaming Client and Network Insights ### Users and Applications Overview The **Netskope WebTx Streaming - Users and Applications Overview** dashboard in Sumo Logic provides visibility into user behavior and application usage across web traffic. It surfaces top users with policy violations, login and logout trends, most-used applications, and application categories. Sanctioned versus unsanctioned traffic comparisons and Cloud Confidence Level (CCL) ratings help teams manage shadow IT risk and enforce application governance policies.
Netskope WebTx Streaming Users and Applications Overview ## Create monitors for Netskope WebTx Streaming app import CreateMonitors from '../../reuse/apps/create-monitors.md'; ### Netskope WebTx Streaming alerts | Name | Description | Trigger Type (Critical / Warning / MissingData) | Alert Condition | | :------------------------------------------------------------------------------------------ | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :---------------------------------------------- | :-------------- | | `Netskope WebTx Streaming - Embargoed Geo Locations of Clients Performing Web Transactions` | This alert is triggered when access is detected and logged from client IP addresses geolocated in embargoed or sanctioned regions. This ensures compliance with regulations and corporate policies. | Critical | Count > 0 | | `Netskope WebTx Streaming - Embargoed Geo Locations of Servers of Web Transactions` | This alert is triggered when access is detected and logged from server IP addresses geolocated in embargoed or sanctioned regions. This ensures compliance with regulations and corporate policies. | Critical | Count > 0 | | `Netskope WebTx Streaming - File Transfer to Embargoed Location` | This alert is triggered when file transfers occur to embargoed or restricted geographic locations, flagging potential compliance violations or data-exfiltration risks for timely review and response. | Critical | Count > 0 | | `Netskope WebTx Streaming - High Latency in Web Requests` | This alert is triggered when web request response times exceed 5 seconds, which may indicate server overload, network issues, or a potential DDoS attack. You can adjust the threshold variable to match your requirements. | Critical | Count > 0 | | `Netskope WebTx Streaming - Large Data Download Events` | This alert is triggered when a download transaction exceeds an abnormally large size (greater than 500MB), helping detect potential data exfiltration or misuse of cloud storage services. You can also adjust the `threshold` variable in the monitor query to match your requirements. | Critical | Count > 0 | | `Netskope WebTx Streaming - Sanctioned Application Access Detected` | This alert is triggered when users access cloud applications tagged as “Sanctioned” beyond a defined threshold, indicating possible shadow IT usage that violates organizational policy. | Warning | Count > 5 | | `Netskope WebTx Streaming - Suspicious Login from Unusual Location` | This alert is triggered when logins originate from geographic locations that deviate from typical user behavior patterns, which may indicate account compromise or unauthorized access. | Critical | Count > 0 | | `Netskope WebTx Streaming - Unauthorized Access Attempts` | This alert is triggered when unauthorized access attempts (401/403) are detected in web transactions, highlighting unusually frequent failures across users or devices for timely investigation. | Critical | Count > 2 | ## Upgrading/Downgrading the Netskope WebTx Streaming app (Optional) import AppUpdate from '../../reuse/apps/app-update.md'; ## Uninstalling the Netskope WebTx Streaming app (Optional) import AppUninstall from '../../reuse/apps/app-uninstall.md';