With the below query I am able to get data as below(first one) and I need to convert it as second box For the time field I am getting common values and i need to merge and combine them as shown. is there any way to achieve this, I've tried with values() but it is not working sourcetype=access_combined | eval action = if(isnull(action) OR action="", "unknown", action) | bin _time span=102h |eval Time=strftime(_time,"%Y-%m-%d %H:%M:%S") | stats count as totals by action,Time | sort -Time,action
... View more