Splunk Search

Dynamic Search Query Based on Field Value

normand1
Engager

I'm trying to create a search that always looks for the responses from the latest version of my app. The `version` field is already defined and the values are something like 1.0, 1.1 or 1.2.

Currently, anytime I update my app I need to update my search query to look for the new version (version=1.3)

I want to do something like "version=my_latest_version" where my_latest_version is a dynamic value that returns the max value of all current "version" field values.

is this possible?

Thanks!

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

A few ways to address this

1. Have a lookup file where you have the latest version in a field called version and then the query does

[ | inputlookup version.csv | table version ]

 but this will need updating, but would be useful if you have many queries that use this field.

2. Run a saved search that searches for the latest version once a day and updates the value in the CSV file used above - makes (1) automated

3. Run the subsearch like @to4kawa refers to, but that will mean that you will have to search all data to get the version before then using that output to search only the latest data set - depending on the data size it could be inefficient.

 

to4kawa
Ultra Champion

| eventstats max(version) as my_latest_version

yes, it is possible.

Tags (1)
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...