Use the Catalog filters and Machine Data Lake-specific dataset details to find raw tables, promoted datasets, and related promotion jobs.
Your Splunk role must grant view access to datasets in the Catalog.
For general Catalog steps, such as opening the Catalog, filtering by keyword, sorting columns, and using the side panel, see Find relevant datasets and Investigate dataset contents.
Use this task to identify the Machine Data Lake-specific dataset type, metadata, and next action.
- From the global navigation bar in Splunk Cloud Platform, select the Catalog (
) icon.
- On the Catalog page, in the Datasets tab, find the Machine Data Lake dataset you need.
Use the general Catalog filtering controls to search by keyword, dataset name, type, creator, or sorted columns. For Machine Data Lake datasets, you can also filter with source, sourcetype, host, and time when that metadata is available.
Note: For recently promoted datasets, especially datasets created from large promotion jobs, default field-value filters such as source, sourcetype, host, and time might not find the promoted dataset immediately after the promotion job completes. Search by dataset name, open the promoted dataset from the promotion job details, or allow more time for metadata in the Catalog to refresh.
- Use the dataset type to understand what you can do next.
-
Raw table: search the raw table for validation or promote selected data when you need a faster or more structured path.
-
Analytics table: search the promoted dataset when you need structured analysis of selected raw data.
-
Splunk index: search the promoted dataset or local Splunk platform index through the supported Splunk search path.
-
Federated dataset: search data that remains in another supported system. Federated datasets are not Machine Data Lake raw tables.
- Select a dataset row and review the Machine Data Lake-specific details.
For raw tables, review event range, size, max rolling window, field information, lineage details where available, and outbound promotion jobs. For promoted datasets, review the source raw table, recent promotion jobs, and the available search action.
Available details depend on the dataset type and your permissions.
- Choose the next action for the dataset:
-
To validate or investigate data, see Search Machine Data Lake data from the Catalog.
-
To make a raw table available for higher-performance search, richer field visibility, dashboards, alerting, or downstream analytics, see Promote data to a Splunk index or Promote data to an analytics table.
-
To review promotion job state, configuration, source dataset, or promoted dataset details, see Monitor and manage promotion jobs.
-
Update dataset settings or delete a dataset where those actions are available to you.
You identify the relevant Machine Data Lake dataset and choose whether to search, promote, inspect related promotion jobs, or manage the dataset.