Overview
This article provides guidance for resolving common issues encountered when using DSPM with a locally deployed DLP appliance.
Common Troubleshooting Scenarios
Browse the symptoms below to find resolutions for appliance connectivity, sidecar registration, and data classification issues.
Sidecar Cannot Connect to the DLP Appliance
Symptom: The DLP Status column in Administration > Sidecar shows an unhealthy status, or the Test Connection button fails.
Possible Causes and Resolutions:
- Incorrect IP address: Verify the DLP appliance IP address in your Cloud Service Provider (CSP) console or under Settings > Security Cloud Platform > On-Premises Infrastructure. Ensure the IP entered in the Sidecar Pool matches the actual appliance address.
- Appliance unavailable: The DLP appliance may be offline or not correctly tethered to the Netskope console. Verify the appliance is powered on and properly configured.
- Wrong appliance selected: Ensure you select the locally deployed DLP appliance visible to your sidecar network, not a Netskope-hosted appliance.
- Firewall/network issue: The sidecar and DLP appliance must be accessible to one another via HTTPS (port 443). Verify that no firewall rules, security groups, or network segmentation are blocking communication between them.
- SSL handshake failure: If sidecar logs show errors such as “Remote host terminated the handshake” or “SSL peer shut down incorrectly,” verify that no SSL-intercepting proxy is interfering with the connection between the sidecar and DLP appliance.
Sidecar Cannot Register with the DSPM Application
Symptom: The sidecar does not appear in Administration > Sidecar, or the Version and Status columns remain empty.
Possible Causes and Resolutions:
- Invalid token: The most common cause is an incorrect or expired sidecar pool token. Generate a new token and redeploy the sidecar with the updated value.
- DNS resolution failure: If sidecar logs show “Temporary failure in name resolution” or “Name or service not known,” verify that the sidecar has proper DNS resolution and outbound egress to your tenant’s sidecar hostname (
sidecar-<tenant>.goskope.com). - Firewall restrictions: Ensure the sidecar has outbound access on port 443 to the required DSPM endpoints. See Firewall Settings for DSPM-Hosted Instances for the full list.
Classification Results Not Returned
Symptom: After scanning a data store, no classification results appear in DSPM > Classification > Classification Management.
Possible Causes and Resolutions:
- No DLP Profiles enabled: Navigate to DSPM > Classification > DLP Profiles & Rules and verify that at least one DLP Profile is enabled in the Discovery Profile.
- DLP appliance not linked: Verify that the sidecar pool is linked to a DLP appliance in Administration > Sidecar.
- Appliance needs upgrade: Ensure the DLP appliance is running a current version. If the appliance was deployed before the R132 release, it may not support auto-upgrades. Redeploy the appliance using the latest available image.
Classification Requests Timing Out
Symptom: Scans take an unusually long time to complete, or sidecar logs show repeated HTTP 425 responses from the DLP appliance.
Resolution: Reduce the number of DLP Profiles selected in your DSPM Discovery Profile. Having too many profiles enabled simultaneously can cause the appliance to exceed its processing capacity.
DLP Appliance Not Auto-Upgrading
Symptom: Despite being registered on an upgrade schedule, the DLP appliance is not upgrading.
Possible Causes and Resolutions:
- Appliance version too old: Auto-upgrading was introduced in the R132 release. If your appliance was deployed before R132, you must redeploy it using at least the R132 build.
- Appliance powered off during upgrade window: The appliance must be running during the scheduled upgrade window. Upgrades are skipped if the appliance is powered down.
- Insufficient disk space: If the appliance was deployed with less than the recommended disk space (351 GB), upgrades can fill up disk space and fail silently. Redeploy the appliance with adequate storage.
UI Display Issues: Destroyed Sidecar Still Shows
Symptom: After Destroying a Sidecar, It Still Shows in the UI.
Resolution: This is expected behavior. After 1 hour, the sidecar will be considered offline and automatically hidden in the Sidecar Administration page. You can still see it by clicking the “Show Inactive Sidecars” icon.

