Hi Team,
I am looking for the help to created search query for my daily run report which is running 3 time in a day.
we are putting the files in directory which we are monitoring in splunk. is there any way we can grab events from only latest sourcefile?
For example:
Index=abc sourcetype=xyz
source=/opt/app/file1_09092023.csv
source=/opt/app/file2_09102023.csv
source=/opt/app/file3_09112023.csv..... new file can be placed time to time.
I wanted report can be show only events from latest file, is it possible?
Thank you
Please help with answers .