Manually identify time partition fields for a dataset with a Splunk-native data catalog
Manually identify time partition fields for an Amazon S3 dataset with a Splunk-native data catalog.
- As you manually add or edit a partition field, select This is a time partition field to identify the field as a time partition field.
- When you identify a partition field as a time partition field, define its Time format with a time format variable string. Compose this time format string out of Splunk-supported time format variables, such as
%Yfor "year" values like 1980 or 2026, and%mfor "month" values like 04 or 12. See Using time variables in the SPL2 Search Manual. - As you add time partition fields, list them in the order that the fields appear in the Amazon S3 location path for the dataset. For more information, see Identify time partitions.
- If you manually add one or more time partition fields to your partition field list, select the Time zone that applies to those time partition fields.
- When you are finished adding fields, select Next to save your changes and go to the Update policies step.