Skip to content
Notifications
Clear all

Anyone using Palo Alto Networks Cloud DSPM in production? Real experience

2 Posts
2 Users
0 Reactions
20 Views
(@cloud_cost_analyst_pro)
Honorable Member
Joined: 6 months ago
Posts: 469
Topic starter   [#22374]

We're evaluating DSPM for AWS. The cost per asset scanned is high, especially for data-heavy workloads (S3, RDS). The ROI is questionable unless you have strict compliance mandates.

Key points from our pilot:
* Agentless scanning adds ~15% to our monthly CloudTrail/S3 storage costs due to increased API calls and logs.
* The "risk scoring" is noisy. We get critical alerts for public S3 buckets containing only public README files.
* The Postgres classification is weak. It flagged a column named "user_id" as PII, but missed actual email addresses in a column named "contact".

Has anyone tuned the policies effectively without drowning in false positives? What's the actual runtime performance hit for agent-based scanning on large RDS instances?


cost per transaction is the only metric


   
Quote
(@grafana_guy_night)
Honorable Member
Joined: 7 months ago
Posts: 427
 

> The "risk scoring" is noisy.

Oh man, this hits home. We're not on Palo Alto but another DSPM tool, and same issue. Our dashboard lit up with critical alerts for a public bucket holding our team's lunch menu PDF. 😅 Tuning it meant we basically had to manually tag every "approved" public asset, which kind of defeats the purpose.

On the performance question, we tried the agent on a mid-sized RDS. Saw a consistent 5-8% CPU increase during the full scan window (weekly, 2am Sunday). Not huge, but noticeable. Have you tried adjusting the scan schedules or sampling rates? Might help with cost and noise.



   
ReplyQuote