Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Data Loss Prevention Incident Response Integration with Netskope

The Netskope DLP integration supports the ingestion of Data Loss Prevention incidents created on the Netskope Data Loss Prevention deployment. Netskope DLP helps companies to track the usage and movement of sensitive data on various platforms.

After ingestion, you can use the incident management functionalities to remediate the DLP incidents.

Key features

This integration includes the following key features:

  • Multiple profile creation for different Netskope tenants.
  • Automating the creation of ServiceNow DLP incidents from Netskope DLP incidents.
  • Filtering of Netskope DLP incidents.
  • Scheduled ingestion of Netskope DLP incidents that create DLP incidents in ServiceNow.
  • Automatically update object status on Netskope when the DLP state changes in your ServiceNow instance.
  • View the forensic details (violating content) of the DLP Incident on DLP IR Analyst workspace and DLP End user workspace.

    Note: The violating content doesn’t persist in ServiceNow. The content is pulled when the incident is in opened in the workspace.

  • Downloading evidence file directly from Netskope on demand.

    Note: The evidence file doesn’t persist in ServiceNow. The evidence file is pulled when the analyst click on the Download File in the workspace.

  • Notification via email to DLP Admin users on Netskope token expiration.

  • Notification via email is sent to DLP Admin users if it exceeds the defined retry limit for incident API call failures.
  • Netskope also supports integration run process. For more information, see Monitor DLP Integration Run process.

  • Getting started with Netskope DLP integration for Data Loss Prevention
    Review the following information before you start setting up your Netskope DLP integration for Data Loss Prevention.

  • Install and configure the Netskope DLP integration for Data Loss Prevention
    Install and configure the Netskope DLP integration from   ServiceNow Store   ServiceNow AI Platform instance. You can start investigating DLP incidents using the  Netskope DLP incident data.
  • Create a Profile for Netskope DLP integration
    Create an incident profile in your ServiceNow AI Platform instance.
  • Mapping DLP incident status with Netskope
    The incident status mapping section enables the users to provide the mappings between the DLP Incident status in ServiceNow and Netskope Object status.
  • Configure Netskope DLP integration settings
    Modify the  Netskope DLP  integration default system properties.
  • Download evidence files
    Download files that violate the DLP policy on Netskope. Download this file onto your local machine from the DLP IR Analyst workspace and DLP IR End user workspace for approvers.
  • Preview evidence files
    Preview DLP incident evidence files in the DLP IR Analyst workspace.
  • Notifications for users on retry mechanism
    Netskope integration will retry the configured number of times in case of API failures during DLP Incident ingestion.
  • Email notifications on credential expiration
    When the token used in the ServiceNow instance expires, Netskope integration sends out an email notification to users with the DLP Admin (sn_dlir.admin) role.
  • Domain Separation in Netskope DLP integration
    Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.

Parent Topic:DLP integrations

Related topics

Symantec Integration for Data Loss Prevention Incident Response

Data Loss Prevention Incident Response Integration with Proofpoint

Internet Content Adaption Protocol (ICAP) integration for DLP IR

Data Loss Prevention Incident Response with Microsoft