On This Page

Home / Lake/ Direct Access/Configure Netskope Direct Access

Configure Netskope Direct Access

Ship your Netskope data straight into Cribl Lake without a Pipeline, bypassing Cribl Stream.


Use the Netskope Direct Access option to land Netskope data directly into Cribl Lake for search and analysis, without manually managing AWS infrastructure. The Netskope Direct Access source supports the following Netskope telemetry:

  • Cloud Access Security Broker (CASB)
  • Data loss prevention (DLP)
  • Network security

How Netskope Direct Access Works

Netskope Direct Access in Cribl is comprised of four main steps. Here’s an overview of the steps you’ll complete in this guide:

  1. In Netskope, create a Netskope Log Streaming stream with an Amazon S3 destination.
  2. In Cribl Lake, create a Netskope Direct Access Source and generate an External ID for Netskope. Cribl provisions a managed S3 bucket and IAM role.
  3. Create a Lake Dataset on the auto-created Storage Location to hold the data.
  4. Add Cribl connection details in Netskope to enable data transfer.

Learn About the Implementation

The Netskope Direct Access implementation has the following details:

  • You can configure one Netskope Source per Cribl Lake Workspace.
  • You can have many Datasets per Source.
  • Data flows directly from Netskope into your S3 bucket; it doesn’t pass through Cribl infrastructure.
  • Netskope Direct Access only supports v1 Datasets.

Create a Netskope Log Streaming Stream

You’ll need to set up a few things in Netskope before you create the Direct Access Source in Cribl.

  1. In Netskope, create a Log Streaming stream. Select Amazon S3 as the Destination.
  2. Don’t add a Folder Path yet - this will be the Dataset name.
  3. Copy the Netskope Account ID and the Region to use in Cribl.

This is the view in Netskope you’ll need:

Select the Log Streaming stream in Netskope and open the Destination
Select the Log Streaming stream in Netskope and open the Destination

See the Netskope Stream Logs to Amazon S3 documentation for details on where to find these fields.

Create a Netskope Direct Access Source

Create the Source in Cribl Lake so that Cribl can provision the managed S3 bucket and IAM role that Netskope writes to.

  1. In Cribl Lake, select Direct Access in the left navbar.

  2. On the Source step, select Netskope, then select Next.

  3. On the Configuration step, enter the required fields. You’ll need access to your Netskope stream destination to collect some of these field values.

    FieldDescriptionNotes
    Netskope AWS Account IDThe Netskope Account ID associated with the Log Streaming stream. To find this ID, consult the Netskope docs: Stream Logs to Amazon S3.Required.
    DescriptionA descriptive name for this direct access connection.Optional.
    RegionThe Region where the Netskope AWS bucket resides.Required. Must match the Region you configured in the Netskope stream.
    External IDThe Netskope ID you’ll use to form the connection to Cribl Lake. Generate an ID in Cribl and paste it into the External ID field on the Netskope Amazon S3 Destination form.Required.
  4. Select Save. After you select Save, the Netskope Source enters a Provisioning state while Cribl sets up infrastructure. Provisioning usually completes in a few minutes.

  5. When the provisioning completes, you can open the Netskope Direct Access Source to see the IAM role.

Create a Netskope Dataset

Create a Dataset on the auto-created Storage Location to hold and organize the incoming Netskope data.

  1. In Cribl Lake, navigate to Datasets.
  2. Select New Dataset.
  3. Enter an ID. You will copy this value into the Folder Path (Optional) field in Netskope.
  4. Select the Netskope Storage Location.
  5. Add a retention period and select Save.

For more detailed information on Datasets, see Cribl Lake Datasets.

Add Cribl Connection Details in Netskope

These steps are required to get data flowing correctly.

Add the IAM Role in Netskope

  1. Once the Source is Ready in Cribl, open it and copy the IAM role field value.
  2. Navigate to Netskope.
  3. Paste the IAM role in the Netskope IAM role ARN field.
  4. Select Save in Netskope.

Add the Folder Path in Netskope

  1. In Cribl Lake, open the Netskope Dataset.
  2. Copy the Dataset ID.
  3. Navigate to Netskope and paste the Dataset ID into the Folder Path (Optional) field. This grants Netskope the ability to write data to Cribl Lake.

Provisioning Lifecycle

A Netskope Direct Access Source will have one of these statuses after you select Save:

StatusDescription
ProvisioningCribl is provisioning the S3 bucket. Credentials are computed and visible to the Cribl Admin.
ReadyThe S3 bucket is reachable, S3 inventory is configured. You can attach Datasets to this Source.
FailedThe provisioning timed out or hit an unrecoverable error. You must delete the Source and try again.

Query Netskope Data with Cribl Search

Once your Netskope data lands in Cribl Lake, your Netskope Dataset is available in Cribl Search as a cribl_lake Dataset. For details on querying your data, see Search Cribl Lake.