Configure Microsoft Azure dataset details
Provide information about how Splunk software creates the Splunk-native data catalog that facilitates federated searches of your Microsoft Azure dataset.
To run federated searches over a Microsoft Azure dataset, Splunk software requires the dataset be backed by a data catalog that Splunk software creates for your dataset. In this step, you determine how this data catalog is created and managed.
You decide whether its schema is created manually or inferred automatically with a crawler. You optionally ensure whether the data catalog is automatically kept in sync with your dataset as it changes. You provide time field information if your data contains time-series data and you want to make use of time fields in your searches. And you provide partition field information as necessary to facilitate efficient federated searches.
- Your Splunk Cloud Platform deployment user account must have a role with the
edit_connectionsandedit_datasetscapabilities. See Define roles on the Splunk platform with capabilities in the Splunk Cloud Platform Manage Users and Security manual. - You must have completed the Select data store, Configure connection, and Define dataset steps of the Create dataset workflow. See Define a Microsoft Azure dataset.
Your Microsoft Azure dataset is created or is in the process of being created.
On the Datasets listing page you can see the Status of your Microsoft Azure dataset, and you can use that status value to guide your next actions regarding it.
| Status | Description | Action |
|---|---|---|
| Ready | The dataset is available for use in federated searches. |
|
| Processing | The crawler process is running over the dataset. |
If you have selected Discover schema via crawler or Discover partitions via crawler during the Configure dataset step of dataset definition, selection of Create dataset on the Review step causes the crawler process to initiate schema and partition field discovery for the dataset. The crawler process might take a few minutes to complete.
Note: If more than 10 minutes pass and the crawler process is still in Processing status, a dataset setup error might be causing it to fail to complete. Review the current dataset configuration for errors such as an incorrect location path. Then delete the dataset that is stuck in Processing status and try to recreate it without errors.
|
| Needs action | The schema and partitions discovered by the crawler require review and confirmation. |
Go to the Edit page for your Microsoft Azure dataset. Review the schema and partition fields that the crawler has discovered, make edits as necessary, and confirm that you have reviewed the discovered fields. See Review the crawler-discovered schema and partitions for a Microsoft Azure dataset. |
| Error | An error occurred during dataset creation or processing. | Review the configuration for your Microsoft Azure dataset, correct issues, and recreate the dataset if necessary. |