Manage data promotions and datasets

Manage Machine Data Lake promotion jobs and edit or delete datasets through the Catalog in Splunk Cloud Platform.

Select a dataset or the Promotion jobs tab to access features for managing a dataset and its contents.

When you select a dataset, the Catalog opens a side panel where you can edit the configuration of the dataset, promote data from raw tables, or delete the dataset. The available actions depend on your permissions for the selected dataset.

Promote data from a raw table:
  1. Select a dataset, then select Promote and follow the on-screen guidance to create an analytics table or Splunk index that contains a processed subset of data from the raw table.
    Data in a raw table is minimally processed and supports limited search functionality. When you promote data, you process it to be optimized for structured analysis in an analytics table or optimized for searches in a Splunk index. For more information, see Promote data in the Machine Data Lake manual.
Monitor and review promotion jobs:
  1. Select the Promotion jobs tab in the Catalog to review promotion jobs that you own or have permission to manage.

    For each promotion job listed on the page, the Catalog shows details such as the name of the promoted dataset that the job created, the promotion mode that it used, and the status of the job. You can select a promotion job to access actions that depend on the job status. For example, you can pause a promotion job that's in the Active status, or delete a promotion job that's in the Canceled status.

    For more information, see the following pages in the Machine Data Lake manual:

Configure a dataset:
  1. Select a dataset, then use the following actions to edit the dataset configuration, depending on the dataset type:
    Dataset type Action
    Splunk index (non-promoted)

    Select View to go to the Indexes page. Then, select the Actions (Image of the "Actions" icon) icon and select Edit.

    You can specify configurations such as the maximum capacity of the index and how the index retains data in searchable or long-term storage.

    Federated dataset

    Select Edit to edit the dataset in the Data Management app.

    You can specify configurations such as remote storage location for the data and the schema and file format of the stored data.

    Raw table

    Select Manage to configure the selected dataset.

    Use the Manage tab to specify configurations such as data retention limits, promotion limits, Delta sharing, and access control for the dataset. Use the Edit data landing tab to specify how the dataset selects and transforms incoming events before storing them.

    Analytics table or Splunk index promoted from a raw table

    Select Manage to configure the selected dataset.

    You can specify Delta sharing and access control configurations for the dataset.

Delete a dataset:
  1. If you have the required permissions, delete a dataset by selecting it and then selecting Delete from the side panel.
    CAUTION: Before deleting a dataset, make sure that it is not being used as a dependency for any promoted datasets or knowledge objects such as reports, dashboards, and alerts.