After connecting a Data Store in the Netskope DSPM user interface, Netskope DSPM will check to see if it has sufficient permissions to scan the Data Store.
If it doesn’t, one or more error messages will be displayed.
If the permission check is successful, Netskope DSPM will connect to your Data Store, import query logs, sample fields in your Data Store to determine if they contain sensitive data (if configured to do so), import query logs and risk assess all queries (if configured to do so), and generate the Netskope DSPM dashboard.
After logs are copied from your Data Store to Netskope DSPM, the dashboard can be reloaded to show incremental progress during the analysis of queries. For the initial scan, we recommend keeping the Netskope DSPM home page/dashboard open to see if the number of alerts is growing. Once you’ve confirmed that Netskope DSPM is operating properly, you can leave Netskope DSPM alone — if you have set up Notifications, it will send a notification once the full initial scan is complete. On the Data Stores page, you will see a spinner next to the Data Store that is still in the process of connecting.

By default, Redshift keeps 2-5 days of data in its query log tables. Netskope DSPM will only be able to assess queries contained in the Redshift logs. In Snowflake and Google Big Query, Netskope DSPM will be able to scan the last 14 days of queries.

