Splunk® Light (Legacy)

Getting Started Manual

Acrobat logo Download manual as PDF

On October 22, 2021, Splunk Light will reach its end of life. After this date, Splunk will no longer maintain or develop this product.
Acrobat logo Download topic as PDF

About table datasets in Splunk Light

Table datasets, or tables, are a type of dataset that you can create, shape, and curate for a specific purpose. You begin by defining the initial data for the table, such as an index, source type, search string, or existing dataset. Then you edit and refine that table in the Table Editor until it fits the precise shape that you and your users require for later analysis and reporting work.

After you create your table, you can continue to iterate on it over time, or you can share it with others so they can refine it further. You can also use techniques like dataset cloning and dataset extension to create new datasets that are based on datasets you have already created.

You can manage table datasets alongside other dataset types that are available to all users, like data model datasets and lookups. All of these dataset types appear in the Datasets listing page.

Default datasets functionality for users

This table explains what all users can do with datasets by default.

Dataset activity Why this is useful
View dataset contents Check a dataset to determine whether it contains fields and values that you want to work with. For example, you can view lookup table files directly instead of searching their contents in the Search view.
Open datasets in Pivot With Pivot you can design a visualization-rich analytical report or dashboard panel that is based on your dataset. Pivot can also help you discover data trends and field correlations within a dataset.
Extend datasets in Search Extend your dataset as a search, modify its search string as necessary, and save the search as a report, alert, or dashboard panel.

Next steps

Additional dataset features

Additional dataset features are listed in the table.

Dataset activity Why this is useful
Use the Table Editor to create tables You can design sophisticated and tightly-focused collections of event data that fit specific business needs, even if you have minimal SPL skills.
Share and refine tables over time After you create a table you can give other users read or write access to it so they can curate and refine it. For example, you can create a simple dataset, and then pass it to another user with deep knowledge of the source data to shape it for a specific use. You can also extend your dataset and let other people refine the extension without affecting the original dataset.
View field analytics The Table Editor offers a Summarize Fields view that provides analytical information about the fields in your dataset. You can use this knowledge to determine what changes you need to make to the dataset to focus it to your needs.
Extend any dataset as a table Dataset extension enables you to create tables that use the definition of any dataset type as their foundation. This enables you to create tables that are based on lookups and data model datasets and then modify those tables to fit your specific use cases.
Clone tables You can make exact copies of table datasets and save the copy with a new name. Only table datasets can be cloned.
Accelerate tables You can accelerate table datasets in a manner similar to report and data model acceleration. This can be helpful if you are using a very large dataset as the basis for a pivot report or dashboard panel. Once accelerated, the table returns results faster than it would otherwise.

Next steps

Last modified on 14 April, 2017
Explore a dataset in Splunk Light
About data models in Splunk Light

This documentation applies to the following versions of Splunk® Light (Legacy): 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters