Search Machine Data Lake data from the Catalog
Search a raw table or promoted dataset through the search path that its dataset type supports.
You must have search or query permission for the selected raw table or promoted dataset.
The Catalog guide explains how to start a general search from the Catalog and continue working in the Search & Reporting app. See Search, transform, and analyze your data.
Use this task for Machine Data Lake-specific search choices. The supported search behavior depends on whether the dataset is a raw table, an analytics table, or a Splunk index promotion. Raw search helps validate that landed data exists, but raw tables are storage-optimized and might not provide the performance or field behavior expected for active investigations.
The dataset returns results through the supported search path for its type. For raw tables, the results can help confirm that relevant landed events exist before you promote a selected data slice.
If raw search confirms that the data is useful but you need faster search, dashboards, alerts, or analytics, see Choose an MDL data strategy, Promote data to a Splunk index, and Promote data to an analytics table.