Skip to content

Commit e402d09

Browse files
eepstainxsoar-bot
authored andcommitted
Netskope Update (demisto#29463)
1 parent 1ca90c4 commit e402d09

File tree

4 files changed

+17
-7
lines changed

4 files changed

+17
-7
lines changed

Diff for: Packs/Netskope/ModelingRules/NetskopeEventCollector_1_3/NetskopeEventCollector_1_3.xif

+8-4
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,8 @@ filter source_log_event = "page"
4040
xdm.target.location.longitude = to_float(dst_longitude),
4141
xdm.target.location.region = dst_region,
4242
xdm.target.location.timezone = dst_timezone,
43-
xdm.target.port = dstport,
43+
xdm.target.port = to_integer(dstport),
44+
xdm.source.port = to_integer(srcport),
4445
xdm.target.sent_bytes = server_bytes,
4546
xdm.target.url = page,
4647
xdm.target.user.identifier = userkey;
@@ -109,7 +110,8 @@ filter source_log_event = "application"
109110
xdm.target.location.longitude = to_float(dst_longitude),
110111
xdm.target.location.region = dst_region,
111112
xdm.target.location.timezone = dst_timezone,
112-
xdm.target.port = dstport,
113+
xdm.target.port = to_integer(dstport),
114+
xdm.source.port = to_integer(srcport),
113115
xdm.target.sent_bytes = server_bytes,
114116
xdm.target.url = coalesce(page, web_url),
115117
xdm.target.user.identifier = userkey;
@@ -178,7 +180,8 @@ filter source_log_event = "alert"
178180
xdm.target.location.longitude = to_float(dst_longitude),
179181
xdm.target.location.region = dst_region,
180182
xdm.target.location.timezone = dst_timezone,
181-
xdm.target.port = dstport,
183+
xdm.target.port = to_integer(dstport),
184+
xdm.source.port = to_integer(srcport),
182185
xdm.target.sent_bytes = server_bytes,
183186
xdm.target.url = coalesce(page, web_url),
184187
xdm.target.user.identifier = userkey;
@@ -219,7 +222,8 @@ filter source_log_event = "network"
219222
xdm.target.domain = type_web,
220223
xdm.target.host.hostname = dsthost,
221224
xdm.target.ipv4 = dstip,
222-
xdm.target.port = dstport,
225+
xdm.target.port = to_integer(dstport),
226+
xdm.source.port = to_integer(srcport),
223227
xdm.target.sent_bytes = server_bytes,
224228
xdm.target.user.identifier = userkey,
225229
xdm.network.http.referrer = referer,

Diff for: Packs/Netskope/ModelingRules/NetskopeEventCollector_1_3/NetskopeEventCollector_1_3_schema.json

+2-2
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@
1717
"is_array": false
1818
},
1919
"dstport": {
20-
"type": "string",
20+
"type": "int",
2121
"is_array": false
2222
},
2323
"hostname": {
@@ -49,7 +49,7 @@
4949
"is_array": false
5050
},
5151
"srcport": {
52-
"type": "string",
52+
"type": "int",
5353
"is_array": false
5454
},
5555
"timestamp": {

Diff for: Packs/Netskope/ReleaseNotes/3_2_3.md

+6
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
2+
#### Modeling Rules
3+
4+
##### Netskope Modeling Rule
5+
6+
Updated the Modeling Rule mapping, adding the srcport field to the XDM xdm.source.port field.

Diff for: Packs/Netskope/pack_metadata.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
"name": "Netskope",
33
"description": "Cloud access security broker that enables to find, understand, and secure cloud apps.",
44
"support": "xsoar",
5-
"currentVersion": "3.2.2",
5+
"currentVersion": "3.2.3",
66
"author": "Cortex XSOAR",
77
"url": "https://www.paloaltonetworks.com/cortex",
88
"email": "",

0 commit comments

Comments
 (0)