Configure Microsoft Azure dataset details
Provide information about how Splunk software creates the Splunk-native data catalog that facilitates federated searches of your Microsoft Azure dataset.
To run federated searches over a Microsoft Azure dataset, Splunk software requires the dataset be backed by a data catalog that Splunk software creates for your dataset. In this step, you determine how this data catalog is created and managed.
You decide whether its schema is created manually or inferred automatically with a crawler. You optionally ensure whether the data catalog is automatically kept in sync with your dataset as it changes. You provide time field information if your data contains time-series data and you want to make use of time fields in your searches. And you provide partition field information as necessary to facilitate efficient federated searches.
- Your Splunk Cloud Platform deployment user account must have a role with the
edit_datasetsandedit_federated_providerscapabilities. See Define roles on the Splunk platform with capabilities in the Splunk Cloud Platform Manage Users and Security manual. - You must have completed the Select data store, Configure connection, and Define dataset steps of the Create dataset workflow. See Define a Microsoft Azure dataset.
-
Ensure your users can access the new dataset with their federated searches. See Give your users role-based access control of remote datasets.
-
Run federated searches over the dataset. See Write and run federated searches over remote datasets with SPL2.