Define a DDSS dataset
Define a Dynamic Data Self Storage (DDSS) dataset in the Data Management app to facilitate federated search of data stored in a specific DDSS location in AWS.
Define a Dynamic Data Self Storage (DDSS) dataset in the Data Management app for use in federated searches. Each DDSS dataset you define lets you run federated searches over data stored in a specific DDSS location in an Amazon S3 bucket without having to reindex it first.
-
You must have a Splunk Cloud Platform (SCP) deployment with dynamic data self storage (DDSS) locations configured in Amazon S3 buckets. See Store expired Splunk Cloud Platform data in your private archive in the Splunk Cloud Platform Admin Manual.
-
Your user account on the SCP deployment must have a role with the
edit_connectionsandedit_datasetscapabilities. See Define roles on the Splunk platform with capabilities in the Splunk Cloud Platform Manage Users and Security manual. -
You must have an AWS account with sufficient permissions to manage the Amazon S3 buckets that serve as locations for your DDSS datasets and apply policies or permissions to them. You also must have permissions that allow you to create and manage SQS queues for those Amazon S3 buckets.
Your DDSS dataset is in the process of being created. This process might take a few minutes to complete.
On the Datasets listing page you can see the Status of your DDSS dataset, and you can use that status value to guide your next actions regarding it.
| Status | Description | Action |
|---|---|---|
| Ready | The dataset is available for use in federated searches. |
|
| Processing | The crawler process is running over the dataset. |
Selection of Create dataset on the Review step causes the crawler process to initiate schema discovery for the dataset. The crawler process might take a few minutes to complete.
Note: If more than 10 minutes pass and the crawler process is still in Processing status, a dataset setup error might be causing it to fail to complete. Review the current dataset configuration for errors such as an incorrect location path. Then delete the dataset that is stuck in Processing status and try to recreate it without errors.
|
| Needs action | The schema discovered by the crawler requires review and confirmation. |
Go to the Edit page for your DDSS dataset. Review the schema that the crawler process has discovered, make edits to it as necessary, and confirm that you have inspected it. See Review the crawler-discovered schema for a DDSS dataset. |
| Error | An error occurred during dataset creation or processing. | Review the configuration for your DDSS dataset, correct issues, and recreate the dataset if necessary. |