Other Usage

How to create a report with event by latest source file?

cbiraris
Path Finder

Hi Team,

I am looking for the help to created search query for my daily run report which is running 3 time in a day.

we are putting the files in directory which we are monitoring in splunk. is there any way we can grab events from only latest sourcefile?

For example: 

Index=abc sourcetype=xyz
source=/opt/app/file1_09092023.csv
source=/opt/app/file2_09102023.csv
source=/opt/app/file3_09112023.csv..... new file can be placed time to time.

I wanted report can be show only events from latest file, is it possible?

Thank you

 

Labels (1)
Tags (1)
0 Karma

cbiraris
Path Finder

Please help with answers .

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...