Edit the CloudWatch Unified Data Store dataset definition and turn its ability to support federated searches off or on.
CloudWatch Unified Data Store datasets, once created, can be edited. You can change certain dataset settings, and you can activate or deactivate the ability to run federated searches over the dataset.
- On your Splunk Cloud Platform deployment, in Splunk Web, select Data Management from the Apps panel.
- Navigate to the Datasets page, locate a CloudWatch Unified Data Store dataset that you would like to edit, and select it.
- Review the sidebar on the right to verify that you have selected the correct dataset. If it is correct, select Edit.
Note:
You can optionally deactivate or activate the CloudWatch Unified Data Store from the listing page sidebar. Under Federated search, select Deactivate if federated search functionality for the dataset is currently activated, or Activate if federated search functionality for the dataset is currently deactivated.
When federated search functionality is deactivated for a CloudWatch Unified Data Store dataset, that dataset cannot be used in federated searches.
- (Optional) Enter or update the Dataset description.
- (Optional) Select the Federated search toggle to activate or deactivate federated search functionality for the dataset. When federated search functionality is deactivated for a CloudWatch Unified Data Store dataset, that dataset cannot be used in federated searches.
- (Optional) Update the S3 table name to identify a different set of CloudWatch data for this dataset to represent.
Note: If you change the S3 table value, the resource access policy for this dataset will be automatically updated. You must reapply the resource access policy to the IAM role that is associated with this dataset and its connection. If you do not do this, federated searches that use this dataset will fail.
- (Optional) Update your Define the time field setting. Select Define the time field if your dataset contains time-series data and you intend to use time-based fields and functions when you run searches over it. Deselect Define the time field if you determine that you don't have time based fields or functions or do not intend to run searches that involve such fields.
- (Optional) If you have updated the S3 table value, Copy the resource access policy and apply it to the AWS IAM role that this dataset and its connection are associated with. See Set the access policy and permissions for a CloudWatch Unified Data Store dataset.
- Select Save to save your changes.
You have updated your CloudWatch Unified Data Store dataset.
If you have not done so already, ensure your users can access your CloudWatch Unified Data Store with their federated searches. See Give your users role-based access control of federated datasets.
If Federated search is activated for your CloudWatch Unified Data Store, run federated searches over its data. See Write and run federated searches over federated datasets with SPL2.