View, update, share, and delete Machine Data Lake raw tables, Splunk indexes, and analytics tables according to your role and dataset permissions.
Dataset actions depend on dataset ownership, role, and capabilities.
-
To update dataset settings, you must have dataset editing or management permission.
-
To configure sharing, you must have sharing or Open Sharing capability.
-
To delete a dataset, you must have the required dataset management permission for that dataset type.
Dataset management actions depend on dataset type, ownership, role, and capabilities. The Catalog uses existing Splunk role-based access control (RBAC), so you see only the datasets and actions that your role permits. If you have administrator permissions, you can manage a broader set of datasets and jobs. You can manage datasets from the dataset row action menu, the details side panel, or the full dataset details page.
- From the global navigation bar in Splunk Cloud Platform, select the Catalog (
) icon.
- On the Catalog page, use the Datasets tab to find the dataset that you want to review.
Review the details panel to confirm the dataset owner, type, retention, source raw table, fields, field values, and promotion history where those details are available.
- Choose the action that matches your goal:
- For a raw Machine Data Lake dataset, select Search to investigate the data or Promote to create a promoted dataset when you have the required permissions.
- For a promoted Machine Data Lake dataset, Splunk local index, or non-MDL federated dataset, select Search when search is supported and you have permission.
- For a non-MDL federated dataset, select the edit action to open the dataset in Unified Datasets when that action is available.
- For a Splunk local index, select the view action to open the Indexes page filtered to that index when that action is available.
- Open the full details page when you need more dataset information or settings.
Raw table details can include Overview, Manage, and landing-related tabs or editor views where supported. Promoted dataset details include Overview and Manage tabs.
- Use the Overview tab to validate the dataset.
Review the metadata, event summary, event range, dataset size, fields, field values, and promotion jobs table. Raw tables can show the maximum rolling window and outbound promotion jobs. Promoted Splunk index datasets can show the source raw table and recent promotion jobs.
Some dataset types show only partial details. For example, Splunk local indexes might have partial metadata, and non-MDL federated datasets show fields only when Splunk has crawled the catalog. Some fields, such as created time or creator, can be blank or unavailable for certain dataset types.
- Use the Manage tab to update editable settings where supported.
For a raw table, you might be able to update the description, raw table retention, promotion retention defaults, access control, and landing settings. For a promoted dataset, you might be able to update the description and query access. Available settings depend on the dataset type and your permissions.
- Manage Open Sharing when your role includes the required sharing capability.
For a raw table, choose a credential expiration policy before you turn on sharing. For an analytics table, download the Open Sharing profile or revoke sharing when you need to stop access. Where supported for the stack and dataset type, Open Sharing provides read-only access through a configured sharing mechanism such as Delta Sharing. You can expire or revoke the profile or token. Splunk can record sharing actions in audit data.
- Update the landing configuration when you need to change which events land in a raw table.
Open the raw table details and use the landing editor or pipeline editor view when that option is available for the dataset.
- Delete a dataset only after you confirm what the deletion affects.
Deletion behavior differs for raw tables, historical promoted datasets, Splunk indexes created by streaming promotion Retention and deletion lifecycle. In the Catalog, select Delete, review the confirmation dialog box, and confirm the deletion only when you are ready to remove the dataset.
If you change a raw table landing definition, verify the data again in the Catalog, see Find Machine Data Lake datasets in the Catalog. If the dataset needs a faster search or analytics path, see Promote data to a Splunk index and Promote data to an analytics table.