Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Data Security Posture Management (DSPM)
    Connecting Data Stores
    AWS Data Stores
    Connect AWS Redshift to DSPM

    Connect AWS Redshift to DSPM

    Overview

    Netskope DSPM supports scanning AWS Redshift data stores. Follow these instructions to setup AWS Redshift and configure its connection to Netskope DSPM.

    Prerequisites:

    • You have database administrator access for the data store.
    • The following are locally-installed:
      • Python (version 3 or higher)
      • PostgreSQL-only: Psycopg PostgreSQL driver for Python
      • AWS-only: AWS CLI
    • Redshift only: you have validated your setup & AWS environment connectivity using the aws configure command.

    Retrieve Connection Information

    Netskope DSPM will require information about your data store in order to communicate with Redshift. Please follow the steps below to identify the connection values for later use within Netskope DSPM.

    1. Click this link to log into your AWS Console, which will navigate you to the Redshift service.
    2. Click Clusters in the left-hand menu.
    3. In the displayed list of clusters, navigate to the Redshift cluster you wish to later connect.
    4. In the General information section, make note of the following values:
    Highlighted ValueExample
    Endpoint
    Port
    Database

    Create a Netskope DSPM Service Account

    A service account within the database is required for connecting your data store with the Netskope DSPM application.  Netskope DSPM provides a Python script which both creates the service account and assigns the necessary non-super user permissions.

    Run Script

    1. Open the command line interface (CLI).
    2. Run the following command to download the script:
    wget https://dasera-release.s3.us-west-2.amazonaws.com/redshift_setup.py
    1. If necessary, navigate to the directory where the script was downloaded.
    2. Run the script.
    3. When prompted, enter the following parameters:
    ParameterValue
    EndpointEnter the corresponding value from the Retrieve Connection Information step above.
    DatabaseEnter the corresponding value from the Retrieve Connection Information step above.
    PortEnter the corresponding value from the Retrieve Connection Information step above.

    Note: 5439 is default Redshift port number. If you are using a custom port number, be sure to substitute it here.
    UsernameUsername of the database administrator running this script
    PasswordPassword of the database administrator running this script
    Username to create for Netskope DSPM userProvide the Database name for which you want to create the Netskope DSPM DB user. dasera_user is recommended, but you can use any value.
    PasswordPassword for the Netskope DSPM DB user

    When the script is complete, the following message (or similar) will be displayed:

    Created user dasera_user with global select access

    Using IAM as Authentication Method

    For Netskope DSPM to authenticate via IAM, you’ll need to give Netskope DSPM the following AWS permission:

    {
      "Action": "redshift:GetClusterCredentials",
      "Resource": [
        "arn:aws:redshift:<region>:<account>:dbuser:<cluster>/<username>",
        "arn:aws:redshift:<region>:<account>:dbname:<cluster>/<database>"
      ]
    }

    Where  <username> is the Redshift User (database username) you created above.

    The redshift:GetClusterCredentials permission allows the Netskope DSPM instance to authenticate as the Redshift User you just created, forgoing the need to provide the user’s password to Netskope DSPM. 

    Note you must specify both a dbuser and dbname resource, and the dbname resource identifiers must cover every database you wish Dasera to scan. As an alternative to listing each database explicitly, you can use wildcards. In the example above, if the 2nd resource is replaced with:

    "arn:aws:redshift:<region>:<account>:dbname:<cluster>/*

    Netskope DSPM will be able to connect (as  <username>) to all databases in the specified cluster.  Similarly:

    "arn:aws:redshift:<region>:<account>:dbname:*/*"

    This will allow Netskope DSPM to connect to all clusters and databases in the given region (provided the database user <username> exists in each cluster).

    If you have Redshift clusters in different regions (but the same AWS account), you will need a unique dbuser and dbname resource lines per unique combination of  <region>, e.g.

    {
      "Action": "redshift:GetClusterCredentials",
      "Resource": [
        "arn:aws:redshift:<region1>:<account>:dbuser:<cluster>/<username>",
        "arn:aws:redshift:<region1>:<account>:dbname:*/*",
        "arn:aws:redshift:<region2>:<account>:dbuser:<cluster>/<username>",
        "arn:aws:redshift:<region2>:<account>:dbname:*/*"
      ]
    }
    If the Netskope DSPM instance is going to be installed in an AWS account that is different from the account(s) running the Redshift cluster(s), IAM is not currently supported. The Dasera instance will need to authenticate via password (see below).

    Connect Your Data Store

    Before attempting to connect an AWS Data Store, be sure you have configured a Netskope DSPM-specific AWS Service Account and onboarded the AWS Infrastructure for this Data Store. For details, please visit our Onboarding AWS Accounts article.

    Step 1: Provide Credentials

    Follow these steps to configure the connection:

    1. Go to Data Stores > Data Store Inventory.

    2. Click CONNECT A DATA STORE in the upper right.

      Tip: Alternatively, if the data store was already found by auto-discovery, go to the Discovered tab and click Connect in the Actions column.

    3. In the Connect a Data Store window, click the data store icon you wish to connect.

    4. In the Provide Credentials section, complete the following fields:

    FieldValue
    Select AWS AccountSelect one of the AWS Accounts defined within the Infrastructure Section screen. The field will default if there is just one AWS Account configured.
    Data Store IdentifierProvide a friendly name to describe this Data Store. Your value is displayed in other Netskope DSPM screens such as Policy Management and Classification Management.
    Data Store EndpointEnter the corresponding value from the Retrieve Connection Information step above, plus the port number and database name.
    For example, for a Public IP address like 1.2.3.4 and database named “example_db”, you would enter 1.2.3.4:5439/example_db.

    Note:
    5439 is default Redshift port number. If you are using a custom port number, be sure to substitute it here.
    Database UsernameEnter the corresponding value from the Create a Netskope DSPM Service Account step above.
    Authentication MethodSelect a type based on your available configurations: AWS Identity Access Management (IAM), RoleUsername/PasswordAWS, Secrets Manager, Self-Managed Secrets Manager
    PasswordEnter the corresponding value from the Create a Netskope DSPM Service Account step above.
    Scan FrequencyControls how often your Data Store is reviewed for changes, Netskope DSPM’s recommended frequency is defaulted, which you can override if (desired).
    Sidecar PoolIf you will use sidecars to monitor this data store, select a sidecar pool with network visibility to said data store. This field is displayed when there is at least one defined sidecar pool.

    To learn more, please visit our Sidecar Administration article.

    Step 2: Scanning Infrastructure

    1. Click Next.
    2. When the Select Capabilities tab appears, complete the following fields:
      • Assign a Data Owner (Optional): Select one or more users responsible for this data store.
      • Which databases should Netskope DSPM scan?: Select the specific data stores and schemas to monitor, if applicable.
      • Features: Select the features you want to enable.
    FeatureSupported for this data store?
    DiscoveryYes (always-on)
    Privileges AnalysisYes
    Shadow Data AnalysisYes
    ClassificationYes
    Data In Use MonitoringYes
    AutomationYes (always-on)

    Step 3: Review and Save

    1. Click Save.
      • When the Review tab appears, the system validates your configuration. If there are any issues, follow the on-screen instructions to fix them.
    2. Click Save to finalize the connection.
    In this Topic
    • Connect AWS Redshift to DSPM