Splunk Search

Dynamic Search Query Based on Field Value

normand1
Engager

I'm trying to create a search that always looks for the responses from the latest version of my app. The `version` field is already defined and the values are something like 1.0, 1.1 or 1.2.

Currently, anytime I update my app I need to update my search query to look for the new version (version=1.3)

I want to do something like "version=my_latest_version" where my_latest_version is a dynamic value that returns the max value of all current "version" field values.

is this possible?

Thanks!

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

A few ways to address this

1. Have a lookup file where you have the latest version in a field called version and then the query does

[ | inputlookup version.csv | table version ]

 but this will need updating, but would be useful if you have many queries that use this field.

2. Run a saved search that searches for the latest version once a day and updates the value in the CSV file used above - makes (1) automated

3. Run the subsearch like @to4kawa refers to, but that will mean that you will have to search all data to get the version before then using that output to search only the latest data set - depending on the data size it could be inefficient.

 

to4kawa
Ultra Champion

| eventstats max(version) as my_latest_version

yes, it is possible.

Tags (1)
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...