My logs have the following info:
userid, version, timestamp
What is the best way to get a report of what product version users are on? I tried:
sourcetype="Apache2" | table timestamp userid version
but it's not exactly what I need. How can you restrict userid to last encountered version, and also search unique userids.
answer by @vskoryk_splunk
.. | stats latest(version) latest(_time) by user
Try this. It will find the most recent event for each userid, which should be the last encountered version.
sourcetype="Apache2" | dedup userid | table timestamp userid version