Edit the Cisco Security Analytics and Logging dataset description and turn off its ability to support federated searches.
Cisco Security Analytics and Logging datasets, once created, can be edited. You can change the description of the dataset, and you can deactivate the ability to run federated searches over the dataset.
- On your Splunk Cloud Platform deployment, in Splunk Web, select Data Management from the Apps panel.
- Navigate to the Datasets page, locate a Cisco SAL dataset that you would like to edit, and select it.
- Review the sidebar on the right to verify that you have selected the correct dataset. If it is correct, select Edit.
Note:
You can optionally deactivate or activate the Cisco Security Analytics and Logging dataset from the listing page sidebar. Under Federated search, select Deactivate if federated search functionality for the dataset is currently activated, or Activate if federated search functionality for the dataset is currently deactivated.
When federated search functionality is deactivated for a Cisco Security Analytics and Logging dataset, that dataset cannot be used in federated searches.
- (Optional) Enter or update the Dataset description.
- (Optional) Select the Federated search toggle to activate or deactivate federated search functionality for the dataset. When federated search functionality is deactivated for a Cisco Security Analytics and Logging dataset, that dataset cannot be used in federated searches.
Note: Cisco Security Analytics and Logging users are not notified when federated search functionality is deactivated for a Cisco Security Analytics and Logging dataset. If you deactivate federated search functionality for a Cisco SAL dataset and you are not the administrator of the Cisco Security Analytics and Logging account that the dataset is connected to, inform the Cisco SAL administrator of the deactivation.
- Select Save to save your changes.
You have updated your Cisco Security Analytics and Logging dataset.
If you have not done so already, ensure your users can access your Cisco Security Analytics and Logging dataset with their federated searches. See Give your users role-based access control of federated datasets.
If Federated search is activated for your Cisco Security Analytics and Logging dataset, run federated searches over its data. See Write and run federated searches over federated datasets with SPL2.