gcloud alpha dlp datasources bigquery inspect Stay organized with collections Save and categorize content based on your preferences.
- NAME
- gcloud alpha dlp datasources bigquery inspect - schedules a job to inspect content in a BigQuery table
- SYNOPSIS
gcloud alpha dlp datasources bigquery inspectINPUT_TABLE[--exclude-info-types][--identifying-fields=[IDENTIFYING_FIELDS,…]][--include-quote][--info-types=[INFOTYPE,…]][--job-id=JOB_ID][--max-findings=MAX_FINDINGS][--max-findings-per-item=MAX_FINDINGS_PER_ITEM][--max-time=MAX_TIME][--min-likelihood=MIN_LIKELIHOOD; default="possible"][--min-time=MIN_TIME][--output-table=OUTPUT_TABLE|--output-topics=[OUTPUT_TOPICS,…]][GCLOUD_WIDE_FLAG …]
- DESCRIPTION
(ALPHA)Schedules a job to inspect content in a BigQuery table forsensitive data.SeeInspectingStorageandDatabasesforSensitiveDataformoredetails.
- EXAMPLES
- The following command creates a job
my-bq-jobto scan records inBigQuery tablemyproject.myds.mytable:gcloudalphadlpdatasourcesbigqueryinspect`myproject.myds.mytable`--job-idmy-ds-job--min-time'2018-01-01T12:00:00Z'--max-time'2018-01-31T12:00:00Z'--output-topicsmy-topic--max-findings-per-item3--max-findings1000--info-typesPHONE_NUMBER,EMAIL_ADDRESS--min-likelihoodvery-likely--include-quote--exclude-info-types - POSITIONAL ARGUMENTS
INPUT_TABLE- BigQuery table to scan. BigQuery tables are uniquely identified by theirproject_id, dataset_id, and table_id in the format
<project_id>.<dataset_id>.<table_id>.
- FLAGS
--exclude-info-types- Whether or not to exclude type information of the findings. Type information isincluded by default.
--identifying-fields=[IDENTIFYING_FIELDS,…]- Comma separated list of references to field names uniquely identifying rowswithin the BigQuery table. Nested fields in the format
person.birthdate.yearare allowed. --include-quote- If True, a contextual quote from the data that triggered a finding is includedin the response. Even if the content is not text, it may be converted to atextual representation in the response. For example, given the input value 'Myphone number is (415) 555-0890' and a search for the infoType PHONE_NUMBER, thecontextual quote would be '(415) 555-0890.'
--info-types=[INFOTYPE,…]- Which infoTypes to scan input for. The values must correspond to infoType valuesfound in documentation. For more information about valid infoTypes, seeinfoTypesReference
--job-id=JOB_ID- Optional job ID to use for the created job. If not provided, a job ID willautomatically be generated. Must be unique within the project. The job ID cancontain uppercase and lowercase letters, numbers, and hyphens; that is, it mustmatch the regular expression:
[a-zA-Z\\d-]+. The maximum length is100 characters. Can be empty to allow the system to generate one. --max-findings=MAX_FINDINGS- Maximum number of findings that will be returned per execution.
If not specified, no limits are applied.
--max-findings-per-item=MAX_FINDINGS_PER_ITEM- Maximum number of findings that will be returned for each item scanned.
If not specified, no limits are applied.
--max-time=MAX_TIME- Scan will include items in repository whose age is >= min-time and <=max-time.
If max-time is omitted then there is no maximum time limit.
See $gcloud topic datetimesfor information on time formats.
--min-likelihood=MIN_LIKELIHOOD; default="possible"- Only return findings equal to or above this threshold.
MIN_LIKELIHOODmust be one of:likely,possible,unlikely,very-likely,very-unlikely. --min-time=MIN_TIME- Scan will include items in repository whose age is >= min-time and <=max-time.
If max-time is omitted then there is no maximum time limit.
See $gcloud topic datetimesfor information on time formats.
- At most one of these can be specified:
--output-table=OUTPUT_TABLE- Publishes results of a Cloud DLP job a BigQuery table. BigQuery tables areuniquely identified by their project_id, dataset_id, and table_id in the format
<project_id>.<dataset_id>.<table_id>or<project_id>.<dataset_id>.<table_id>. If notable_id is specified, DLP will create a table for you. --output-topics=[OUTPUT_TOPICS,…]- Publishes the results of a Cloud DLP job to one or more Cloud Pub/Sub topics.
Note: The topic must have given publishing access rights to the DLP API serviceaccount executing the Cloud DLP job.
- GCLOUD WIDE FLAGS
- These flags are available to all commands:
--access-token-file,--account,--billing-project,--configuration,--flags-file,--flatten,--format,--help,--impersonate-service-account,--log-http,--project,--quiet,--trace-token,--user-output-enabled,--verbosity.Run
$gcloud helpfor details. - API REFERENCE
- This command uses the
dlp/v2API. The full documentation for thisAPI can be found at:https://cloud.google.com/sensitive-data-protection/docs/ - NOTES
- This command is currently in alpha and might change without notice. If thiscommand fails with API permission errors despite specifying the correct project,you might be trying to access an API with an invitation-only early accessallowlist.
Except as otherwise noted, the content of this page is licensed under theCreative Commons Attribution 4.0 License, and code samples are licensed under theApache 2.0 License. For details, see theGoogle Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2025-07-22 UTC.