Splunk Dev

How can I collect data from a newly created table every month?

superhm
Explorer

Hello.

I have been interworking Databases with Splunk.

One of the databases on security solution makes new tables every month like ACCESS_LOG_TABLE_201705
Next month will be created ACCESS_LOG_TABLE_201706

How can I collect data from a newly created table every month?
I can't set up the databases

Is there a way?

Thank you.

Tags (1)
0 Karma

jplumsdaine22
Influencer

Create a view in your database that has the latest table, then get splunk to index the view

0 Karma

superhm
Explorer

I'm using Splunk DB Connect V2

0 Karma

ggssa2000
Explorer

Does the regex help? ACCESS_LOG_TABLE_20[0-1][0-9][0-1][0-9]

0 Karma

superhm
Explorer

I can't use regex. DB Connect V2 has to the view permission table where Drop-Down list, as far as I know.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...