Review the crawler-discovered schema and partitions for an Amazon S3 dataset
Review, edit, and confirm the crawler-discovered schema and partitions for an Amazon S3 dataset that is backed by a Splunk-native data catalog, to ready the dataset for federated search.
-
If you have selected Discover schema via crawler for your dataset, the crawler process discovers the dataset schema.
-
If you have selected Discover partitions via crawler for your dataset, the crawler process identifies the fields by which your dataset is partitioned.
The crawler process might take a few minutes to complete. If it completes without errors, your dataset will have a Status of Needs action.
What does Needs action mean? It means you need to review the schema and partition fields that were discovered by the crawler process, edit them as necessary, and confirm that you have inspected them, so you can use the new Amazon S3 dataset in federated searches.
- A role on your Splunk Cloud Platform deployment with the
edit_connectionsandedit_datasetscapabilities. See Define roles on the Splunk platform with capabilities in the Splunk Cloud Platform Manage Users and Security manual. -
You must have completed the definition of your Amazon S3 dataset and selected Create dataset on the Review page.
-
The Amazon S3 dataset must be backed by a Splunk-native data catalog, and you must have selected either Discover schema via crawler or Discover partitions via crawler (or both) on the Configure dataset step of the dataset definition.
-
On the Datasets list page, your Amazon S3 dataset must have a Status of Needs action.
-
Ensure your users can access the new dataset with their federated searches. See Give your users role-based access control of federated datasets.
-
Run federated searches over the dataset. See Write and run federated searches over federated datasets with SPL2.