Overview
Use the Policies > Alerts page to investigate specific security events and incidents detected by Netskope DSPM. This page provides a detailed breakdown of violations, allowing you to triage risks based on severity, user activity, and policy logic.
Alerts Dashboard
The top section of the page displays three key widgets to help you visualize your current threat landscape:
- Alerts Status: Breakdown of alerts by their current state (Open, Dismissed, Resolved).
- Alerts by Policy Type: A distribution of alerts categorized by the specific policy rule triggered.
- Top Policies by Alerts: Ranking of the policies generating the highest volume of violations.

Alert Details
The main table lists individual security events. Each row represents a specific incident and includes the following details:
| Column | Description |
|---|---|
| Date/Time | The exact time the incident was detected. |
| Policy Name | The specific policy violated by the query or action. Tip: Click the Policy Name to view a summary of the policy’s logic without leaving the page. |
| Policy Type | The category of the security event, such as Data Store Posture, Data Access, Privacy Violation, or Data Exfiltration. |
| Employee/Username | The database username or employee ID responsible for the query. |
| Severity | The risk level assigned to the alert (Critical, High, Medium, Low). |
| Status | The current workflow state of the alert (Open, Dismissed, or Resolved). You can update this status directly using the dropdown menu in this column. |
If your organization uses BI or query tools that share a single database user account, Netskope DSPM can often extract the specific employee’s ID or email from the query metadata to provide accurate attribution. For more details, see Manage DSPM Service Accounts.
Filter and Export Data
To manage large volumes of alerts, use the following tools located at the top of the table:
- Filter: Click the Filter icon (top left) to open the filter drawer. You can refine the list by date range, severity, policy type, user, or status.
- Export: Click CSV Export to download the current view (including applied filters) as a
.csvfile for external analysis or reporting.

