Search, transform, and analyze your data
Run targeted searches on relevant datasets through the Catalog in Splunk Cloud Platform.
After finding the relevant dataset for your investigation, you can run a targeted search on that dataset and start working with the data that you need.
By using the Catalog to find the right dataset, you can avoid running slow and expensive searches that span multiple datasets, such as index=*.
Raw tables can be costly to search and support limited search functionality. To work with data from a raw table, start by identifying the relevant subset of events and promoting them into an analytics table or Splunk index. Then, run your searches on the analytics table or Splunk index instead of the raw table. For more information, see the following pages in the Machine Data Lake manual:
For information about how to create knowledge objects based on your search results, refer to the following documentation:
| Task | Documentation |
|---|---|
| Visualizing your search results in a dashboard | See the Dashboard Studio manual. |
| Saving your search as a report that you can use again at a later time or run on a scheduled interval | See the Reporting Manual. |
| Setting up alerts that notify you when the search results meet specific conditions | See the Alerting Manual. |