Splunk Dev

How can I collect data from a newly created table every month?

superhm
Explorer

Hello.

I have been interworking Databases with Splunk.

One of the databases on security solution makes new tables every month like ACCESS_LOG_TABLE_201705
Next month will be created ACCESS_LOG_TABLE_201706

How can I collect data from a newly created table every month?
I can't set up the databases

Is there a way?

Thank you.

Tags (1)
0 Karma

jplumsdaine22
Influencer

Create a view in your database that has the latest table, then get splunk to index the view

0 Karma

superhm
Explorer

I'm using Splunk DB Connect V2

0 Karma

ggssa2000
Explorer

Does the regex help? ACCESS_LOG_TABLE_20[0-1][0-9][0-1][0-9]

0 Karma

superhm
Explorer

I can't use regex. DB Connect V2 has to the view permission table where Drop-Down list, as far as I know.

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...