I want to count duplicates of certain fields in my data. I am using this search:
..mysearch...| chart count(O_D) as "B_D" by G_B span=1d
| where B_D >1
|stats count ("B_D")
This gives the result I want, but I want to present this in a single value with a trendline. I tried replacing chart with timechart but then the result ends in 0
timechart uses _time. Do _time exist in the previous result?
If you use the time chart, this field name will also be changed. Please also check the field name.
what previous result do you mean? Which field name do you mean? If i run my search, i still see _time in my raw events
Can I provide changed search sentences?
Yes please
or did i understand you wrong?