Splunk Search

Indexing mySQL database

antlefebvre
Communicator

I am attempting to index a mySQL database as searching for me is much easier using the SPL. I currently have a DB Connect tie into the mySQL database. I have been able to connect and index a single table, but there are over 1900 tables. About 500 are empty. I am only looking for tables that are being updated. Does anyone know of a query to get the tables that are actively being written to in the database?

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee
0 Karma

antlefebvre
Communicator

That is how I was able to determine that 500 tables are empty. But I'm looking in particular for the tables that are actively being written to. Tables that have static values I am uninterested in adding.

0 Karma
Get Updates on the Splunk Community!

Extending Splunk AI Assistant for SPL to Splunk Enterprise customers!

Howdy Splunk Community! It’s an exciting day here at Splunk – Splunk AI Assistant for SPL version 1.3.0 is now ...

Developer Spotlight with Qmulos

Qmulos: Building a Next-Level Cybersecurity Business through Splunk Apps Qmulos started as a scrappy startup ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Enhance Security Operations with Automated Threat Analysis in the Splunk EcosystemAre you leveraging ...