Manage a DDSS dataset

Edit a DDSS dataset after it is created.

DDSS datasets, once created, can be edited. You can update the dataset description, review and edit its schema, activate knowledge object discovery for searches of the dataset, and more.
Note: If you are trying to resolve a dataset Status of Needs action, see Review the crawler-discovered schema for a DDSS dataset.
  • You must have a Splunk Cloud Platform (SCP) deployment with dynamic data self storage (DDSS) locations configured in Amazon S3 buckets. See Store expired Splunk Cloud Platform data in your private archive in the Splunk Cloud Platform Admin Manual.

  • Your user account on the SCP deployment must have a role with the edit_connections and edit_datasets capabilities. See Define roles on the Splunk platform with capabilities in the Splunk Cloud Platform Manage Users and Security manual.

  • You must have an AWS account with sufficient permissions to manage the Amazon S3 buckets that serve as locations for your DDSS datasets and apply policies or permissions to them. You also must have permissions that allow you to create and manage SQS queues for those Amazon S3 buckets.

  1. On your Splunk Cloud Platform deployment, in Splunk Web, select Data Management from the Apps panel.
  2. Navigate to the Datasets page, locate a DDSS dataset that you would like to edit, and select it.
  3. Review the sidebar on the right to verify that you have selected the correct dataset. If it is correct, select Edit.
    Note:

    You can optionally deactivate or activate federated search functionality for the DDSS dataset from the listing page sidebar. Under Federated search, select Deactivate if federated search functionality for the dataset is currently activated, or Activate if federated search functionality for the dataset is currently deactivated.

    When federated search functionality is deactivated for a DDSS dataset, that dataset cannot be used in federated searches.

  4. (Optional) Enter or update the Dataset description.
  5. (Optional) Review and update the Schema. You can update, add, and delete fields, and you can change the schema order. If you use the JSON view, see the material about the data schema (dataSchema) inJSON standards for the data and partition schemas.
  6. (Optional) Update the SQS queue ARN as necessary to ensure dataset and catalog consistency. For more information, see Set up automated updates for a Splunk-native DDSS data catalog in AWS.
  7. (Optional) Activate Knowledge object discovery at search time to run federated searches over your DDSS dataset that include knowledge objects such as extracted fields, field aliases, calculated fields, event types, and tags.

    Knowledge object discovery is based on the inferred source types in your DDSS dataset. When your dataset is created, you can see the source types that the crawler service inferred for your dataset, and then use those source types in your searches. Go to the Datasets listing page, select the dataset, and note the source types listed under Sourcetype in the dataset detail sidebar.

    For more information, see Activate knowledge object discovery for federated searches of DDSS datasets.

    Note: When Knowledge object discovery at search time is activated for a DDSS dataset, federated searches of that dataset might take longer to complete.
  8. (Optional) Review the generated policies and reapply them to your AWS account if you are encountering AWS access issues. For more information, see the Update policies guidance in Define a DDSS dataset.
  9. Select Save to save your changes.
You have updated your DDSS dataset.

If you have not done so already, ensure your users can access your DDSS dataset with their federated searches. See Give your users role-based access control of federated datasets.

If Federated search is activated for your Cisco Security Analytics and Logging dataset, run federated searches over its data. See Write and run federated searches over federated datasets with SPL2.