Hello.
I have been interworking Databases with Splunk.
One of the databases on security solution makes new tables every month like ACCESS_LOG_TABLE_201705
Next month will be created ACCESS_LOG_TABLE_201706
How can I collect data from a newly created table every month?
I can't set up the databases
Is there a way?
Thank you.
Create a view in your database that has the latest table, then get splunk to index the view
I'm using Splunk DB Connect V2
Does the regex help? ACCESS_LOG_TABLE_20[0-1][0-9][0-1][0-9]
I can't use regex. DB Connect V2 has to the view permission table where Drop-Down list, as far as I know.