Review the crawler-discovered schema for a DDSS dataset

Ready a DDSS dataset for federated search by reviewing, editing, and confirming its crawler-discovered schema.

When you are wrapping up DDSS dataset definition and you select Create dataset on the Review step, a crawler process launches that scans the dataset to discover its schema.

The crawler process might take a few minutes to complete. If it completes without errors, your DDSS dataset will have a Status of Needs action.

What does Needs action mean? It means you need to review the schema that the crawler process discovered, edit it as necessary, and confirm that you have inspected it, so you can use the new DDSS dataset in federated searches.

Note: If your DDSS dataset has a Status of Ready and you just want to edit it, see Manage a DDSS dataset.
  • A role on your Splunk Cloud Platform deployment with the edit_connections and edit_datasets capabilities. See Define roles on the Splunk platform with capabilities in the Splunk Cloud Platform Manage Users and Security manual.
  • You must have completed the definition of your DDSS dataset and selected Create dataset on the Review page.

  • On the Datasets list page, your DDSS dataset must have a Status of Needs action.

  1. In the Data Management app, on the Datasets list page, select a DDSS dataset with a Status of Needs action.

    You can use the filter on the Status column to quickly find DDSS datasets that have the Needs action status:An icon that looks like a funnel. When the filter is active, the icon changes from an outline of a funnel to a fully shaded-in funnel.. Select the filter icon and choose the status value you want to filter on.

  2. In the right-hand sidebar, select Edit.
  3. On the Edit page, go to the Schema section to review the schema fields that the crawler process discovered for your dataset and update the schema if necessary.
    Note: The following schema update options assume that you are using the Field list view for the schema. You can also edit, delete and add schema fields through the JSON view. Your input must match the JSON data schema (dataSchema). See JSON standards for the data and partition schemas.
    1. (Optional) Edit schema errors. You can change the Name and Data type of any given schema field, and you change the schema order so that it fits the actual schema in your dataset.
    2. (Optional) Delete fields that do not belong in the schema.
    3. (Optional) Replace fields that are missing from the schema by selecting Add field.
    4. Select I confirm that I have reviewed the schema.
  4. Select Save to save your changes.
Your DDSS dataset is ready to be used in federated searches.
Now that this dataset is ready to be shared and searched, do these things:

You can also go to the Edit page for the dataset at any time to change other settings for the dataset. See Manage a DDSS dataset.