My logs have the following info:
userid, version, timestamp
What is the best way to get a report of what product version users are on? I tried:
sourcetype="Apache2" | table timestamp userid version
but it's not exactly what I need. How can you restrict userid to last encountered version, and also search unique userids.
answer by @vskoryk_splunk
.. | stats latest(version) latest(_time) by user
http://docs.splunk.com/Documentation/Splunk/6.1/SearchReference/Commonstatsfunctions
Try this. It will find the most recent event for each userid, which should be the last encountered version.
sourcetype="Apache2" | dedup userid | table timestamp userid version