Skip to main content

What this integration contributes

Netskope can contribute normalized web, cloud, authentication, data-protection, and threat activity. Reviewed examples include:
  • web.ai.visited — AI website visited
  • data.bulk.uploaded — bulk data upload
  • geo.impossible — impossible travel between sign-ins
The current connection uses REST API v2; a legacy REST variant may appear for existing customers. See how integration data becomes signals.

What Living Security needs

Endpoint access required: Required role: Tenant Admin or equivalent with access to Settings → Tools
This integration requires a v2 API token, not a v1 token. V1 tokens use query parameter authentication and will not work with the v2 API endpoint.

Prerequisites

  • You must have Tenant Admin access in Netskope to manage REST API tokens.

Part A — In Netskope

Your Netskope administrator completes these steps.
1

Navigate to REST API v2 Token Management

  1. Sign in to your Netskope admin console at https://<tenant>.goskope.com.
  2. In the left navigation, click Settings.
  3. Under Tools, select REST API v2.
2

Create a new token

  1. Click New Token.
  2. Enter a descriptive name (e.g., Living Security Platform).
  3. Under endpoint access, enable access to:
Grant both endpoints. They feed two separate streams — alerts and events — and a token scoped to only one of them still connects successfully. The stream behind the missing endpoint then returns nothing, with no error to tell you why.
These two are the only endpoints Living Security requires. Granting nothing beyond them follows least privilege.
  1. Click Save (or Generate Token).
3

Copy and save your token

Copy the token immediately and store it securely.
Netskope displays the token value only once at creation. If you navigate away without copying it, you must delete the token and create a new one.
4

Configure IP allowlist (if applicable)

If your Netskope tenant has IP allowlisting enabled, you must add Living Security’s egress IP ranges.
  1. In the Netskope admin console, go to Settings → Administration → IP Allowlist.
  2. If IP allowlisting is enabled, add each Living Security egress IP address to the Custom IP list.
If IP allowlisting is enabled, the connection dialog will succeed, but data syncs will fail with 401 Unauthorized until the correct IPs are added.
5

Identify your tenant subdomain

Your tenant subdomain is the prefix of your Netskope admin console URL.If your console URL is https://acme.goskope.com, your subdomain is acme.Enter the bare subdomain only — no https://, no .goskope.com, no trailing slash.
The connection dialog accepts several input forms (bare subdomain, full hostname, or full URL) and normalizes automatically. However, entering the bare subdomain is recommended.

Part B — In the Living Security Platform

The program owner completes this step, or the system admin if using delegated setup.
You are now connected to Netskope (v2 API).

Troubleshooting

Common causes:
  1. Token revoked or expired — generate a new token
  2. Using a v1 token — v1 tokens authenticate via query parameter and won’t work with v2 endpoints. Generate a new v2 token from Settings → Tools → REST API v2
  3. IP allowlist blocking requests — if your tenant has IP allowlisting enabled, verify all four Living Security egress IP addresses are on the allowlist
The token was created without access to /api/v2/events/data/alert or /api/v2/events/data/page. Token endpoint permissions cannot be changed after creation — create a new token with read access to both and reconnect.
The token is missing one of the two required endpoints. A token scoped to only /api/v2/events/data/alert or only /api/v2/events/data/page still connects, and the stream behind the missing endpoint stays silently empty.Endpoint permissions cannot be changed after a token is created — generate a new token with read access to both, then reconnect.
If IP allowlisting is enabled, Living Security’s egress IP addresses may have changed. Check Configuring Integration Egress IP Addresses and update the Custom IP list to match.
V1 and v2 tokens use different authentication mechanisms:
  • v1: Query parameter (token=...)
  • v2: Header (Netskope-Api-Token: ...)
Living Security uses v2 authentication. Generate a new token from Settings → Tools → REST API v2 (not the legacy v1 token page).