Splunk Search

Dynamic Search Query Based on Field Value

normand1
Engager

I'm trying to create a search that always looks for the responses from the latest version of my app. The `version` field is already defined and the values are something like 1.0, 1.1 or 1.2.

Currently, anytime I update my app I need to update my search query to look for the new version (version=1.3)

I want to do something like "version=my_latest_version" where my_latest_version is a dynamic value that returns the max value of all current "version" field values.

is this possible?

Thanks!

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

A few ways to address this

1. Have a lookup file where you have the latest version in a field called version and then the query does

[ | inputlookup version.csv | table version ]

 but this will need updating, but would be useful if you have many queries that use this field.

2. Run a saved search that searches for the latest version once a day and updates the value in the CSV file used above - makes (1) automated

3. Run the subsearch like @to4kawa refers to, but that will mean that you will have to search all data to get the version before then using that output to search only the latest data set - depending on the data size it could be inefficient.

 

to4kawa
Ultra Champion

| eventstats max(version) as my_latest_version

yes, it is possible.

Tags (1)
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Supercharging Windows Security Detection Performance: Introducing Hybrid Field ...

Windows event logs—from Security auditing and Sysmon to PowerShell script blocks—form the operational backbone ...

Ditch the Manual Grind: Building AI Agents with Splunk

Ditch the Manual Grind: Building AI Agents with Splunk Let’s be real: your team’s time is being eaten alive. ...

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...