---
sourceDocument: Zurich Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/security-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Data Loss Prevention Incident Response Integration with Netskope

# Data Loss Prevention Incident Response Integration with Netskope {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Netskope DLP integration supports the ingestion of Data Loss Prevention incidents created on the Netskope Data Loss Prevention deployment. Netskope DLP helps companies to track the usage and movement of sensitive data on various platforms.

After ingestion, you can use the incident management functionalities to remediate the DLP
incidents.

## Key features {#dlp-incident-response-integration-netskope__section_lkk_vnh_3tb}

This integration includes the following key features:

* Multiple profile creation for different Netskope tenants.
* Automating the creation of ServiceNow DLP incidents from Netskope DLP incidents.
* Filtering of Netskope DLP incidents.
* Scheduled ingestion of Netskope DLP incidents that create DLP incidents in ServiceNow.
* Automatically update object status on Netskope when the DLP state changes in your ServiceNow instance.
* View the forensic details (violating content) of the DLP Incident on DLP IR Analyst workspace and DLP End user workspace.  
  Note:  
  The violating content doesn't persist in ServiceNow. The content is pulled when the incident is in opened in the workspace.
* Downloading evidence file directly from Netskope on demand.  
  Note:  
  The evidence file doesn't persist in ServiceNow. The evidence file is pulled when the analyst click on the Download File in the workspace.
* Notification via email to DLP Admin users on Netskope token expiration.
* Notification via email is sent to DLP Admin users if it exceeds the defined retry limit for incident API call failures.
* Netskope also supports integration run process. For more information, see [Monitor DLP Integration Run process](https://www.servicenow.com/docs/hOB1ot27bNzgjZQgsLDaIQ "Track and monitor the ongoing ingestion or the integration run process. The integration run processes contains the statistics on how much the data was processed and the integration status.").
{#dlp-incident-response-integration-netskope__ul_r13_xnh_3tb}
* **[Getting started with Netskope DLP integration for Data Loss Prevention](https://www.servicenow.com/docs/Z~6NOv9oJW77lcR~EJX23g)**   
  Review the following information before you start setting up your Netskope DLP integration for Data Loss Prevention.
* **[Install and configure the Netskope DLP integration for Data Loss Prevention](https://www.servicenow.com/docs/_je1CvOEEOTiOgaetfkVuw)**   
  Install and configure the Netskope DLP integration from   ServiceNow Store   ServiceNow AI Platform instance. You can start investigating DLP incidents using the  Netskope DLP incident data.
* **[Create a Profile for Netskope DLP integration](https://www.servicenow.com/docs/4EzLHler0j3GHYghqP~G3Q)**   
  Create an incident profile in your ServiceNow AI Platform instance.
* **[Mapping DLP incident status with Netskope](https://www.servicenow.com/docs/n1tcxOXe7RQN1ULH7cf33w)**   
  The incident status mapping section enables the users to provide the mappings between the DLP Incident status in ServiceNow and Netskope Object status.
* **[Configure Netskope DLP integration settings](https://www.servicenow.com/docs/JPSXAgfRLqJKEu41KDVtdg)**   
  Modify the  Netskope DLP  integration default system properties.
* **[Download evidence files](https://www.servicenow.com/docs/a7~RduQlTgSB3jqrjVXsSg)**   
  Download files that violate the DLP policy on Netskope. Download this file onto your local machine from the DLP IR Analyst workspace and DLP IR End user workspace for approvers.
* **[Preview evidence files](https://www.servicenow.com/docs/5QQfQx~JV8SqUdsWZ7zJmw)**   
  Preview DLP incident evidence files in the DLP IR Analyst workspace.
* **[Notifications for users on retry mechanism](https://www.servicenow.com/docs/S5gmL9oLfPQnzFyEf8f37g)**   
  Netskope integration will retry the configured number of times in case of API failures during DLP Incident ingestion.
* **[Email notifications on credential expiration](https://www.servicenow.com/docs/Ro2qGx4TjtAC9DMMSesdWw)**   
  When the token used in the ServiceNow instance expires, Netskope integration sends out an email notification to users with the DLP Admin (sn_dlir.admin) role.
* **[Domain Separation in Netskope DLP integration](https://www.servicenow.com/docs/hDuNWLf1K7FnDQyokD95ng)**   
  Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.

**Related concepts**   

* [Symantec Integration for Data Loss Prevention Incident Response](https://www.servicenow.com/docs/aObXXiVM1lQvXJKsNS8QJA "The Symantec DLP integration supports the ingestion of Data Loss Prevention Incident Response incidents created on the Symantec Data Loss Prevention Incident Response deployment. After ingestion, you can use the incident management functionalities to remediate the DLP incidents.")
* [Data Loss Prevention Incident Response Integration with Proofpoint](https://www.servicenow.com/docs/vKXSmLnH_RNWq6t6uULo2A "The Proofpoint DLP integration supports the ingestion of Data Loss Prevention incidents created on the Proofpoint Data Loss Prevention deployment. After ingestion, you can use the incident management functionalities to remediate the DLP incidents.")
* [Internet Content Adaption Protocol (ICAP) integration for DLP IR](https://www.servicenow.com/docs/ByR7~8HlyuGKCs8~4oxOZw "The Internet Content Adaption Protocol (ICAP) DLP integration supports the ingestion of Data Loss Prevention Incident Response alerts, allows the fetching of match content, and evidence files from Amazon S3 created on the ICAP supported Data Loss Prevention Incident Response deployment.")
* [Data Loss Prevention Incident Response with Microsoft](https://www.servicenow.com/docs/yOAYmAohK0dG7M~GxQEvzQ "The Data Loss Prevention Incident Response with Microsoft provides a core framework to import Data Loss Prevention (DLP) incidents from multiple sources, such as Microsoft Purview apps, Microsoft Teams, Exchange Online, SharePoint Online, OneDrive for Business, and other event types.")

