I have a file, which will be updated multiple times in a single day and the it will be indexed into splunk multiples times in a day, but i want to display the very latest/recently updated file.
how do i do that?
not sure if i understand exactly what you're asking...but given a sourcetype, this will run a subsearch to find the source with the latest timestamped event and use that source to limit your main search.
index=your_index sourcetype=your_sourcetype [|tstats latest(source) as source where index=your_index AND sourcetype=your_sourcetype | table source]