Review the crawler-discovered schema for a DDSS dataset
Ready a DDSS dataset for federated search by reviewing, editing, and confirming its crawler-discovered schema.
When you are wrapping up DDSS dataset definition and you select Create dataset on the Review step, a crawler process launches that scans the dataset to discover its schema.
The crawler process might take a few minutes to complete. If it completes without errors, your DDSS dataset will have a Status of Needs action.
What does Needs action mean? It means you need to review the schema that the crawler process discovered, edit it as necessary, and confirm that you have inspected it, so you can use the new DDSS dataset in federated searches.
- A role on your Splunk Cloud Platform deployment with the
edit_connectionsandedit_datasetscapabilities. See Define roles on the Splunk platform with capabilities in the Splunk Cloud Platform Manage Users and Security manual. -
You must have completed the definition of your DDSS dataset and selected Create dataset on the Review page.
-
On the Datasets list page, your DDSS dataset must have a Status of Needs action.
-
Ensure your users can access the new dataset with their federated searches. See Give your users role-based access control of federated datasets.
-
Run federated searches over the dataset. See Write and run federated searches over federated datasets with SPL2.
You can also go to the Edit page for the dataset at any time to change other settings for the dataset. See Manage a DDSS dataset.