Netskope CASB policy enforcement gaps: alert-only on sensitive activity or volume anomaly
This rule monitors Netskope cloud application events to detect potential data exfiltration. It triggers if there is a significant volume anomaly (z-score >= 2) for any cloud application activity, or if a 'Share' or 'Upload' activity occurs that is only configured to 'Alert' rather than being blocked. This helps identify unusual spikes in data movement or sensitive operations that bypass formal enforcement controls.
Splunk (SPL)

