Splunk Search

Dynamic Search Query Based on Field Value

normand1
Engager

I'm trying to create a search that always looks for the responses from the latest version of my app. The `version` field is already defined and the values are something like 1.0, 1.1 or 1.2.

Currently, anytime I update my app I need to update my search query to look for the new version (version=1.3)

I want to do something like "version=my_latest_version" where my_latest_version is a dynamic value that returns the max value of all current "version" field values.

is this possible?

Thanks!

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

A few ways to address this

1. Have a lookup file where you have the latest version in a field called version and then the query does

[ | inputlookup version.csv | table version ]

 but this will need updating, but would be useful if you have many queries that use this field.

2. Run a saved search that searches for the latest version once a day and updates the value in the CSV file used above - makes (1) automated

3. Run the subsearch like @to4kawa refers to, but that will mean that you will have to search all data to get the version before then using that output to search only the latest data set - depending on the data size it could be inefficient.

 

to4kawa
Ultra Champion

| eventstats max(version) as my_latest_version

yes, it is possible.

Tags (1)
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and stall ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...