Hi, I didn't find anything about this while searching so here's my question. I'm working on the proving a negative problem, adding appendpipe after a stats in order to display a result of 0 for each day for the period of time I need. I usually do this for a single row, however I need to have multiple rows for multiple days as output for stats or more importantly timechart. I ran into a scenario I cannot explain and wanted to understand further. While testing I created this search: | makeresults
| eval value=0, category="test", _time=strftime(now(), "%H")
| appendpipe
[| eval value=0, category="test", _time=relative_time(now(), "-1d@d") ]
| appendpipe
[| eval value=0, category="test", _time=relative_time(now(), "-2d@d")]
| appendpipe
[| eval value=0, category="test", _time=relative_time(now(), "-3d@d")]
| appendpipe
[| eval value=0, category="test", _time=relative_time(now(), "-4d@d")]
| appendpipe
[| eval value=0, category="test", _time=relative_time(now(), "-5d@d")]
| appendpipe
[| eval value=0, category="test", _time=relative_time(now(), "-6d@d")]
| appendpipe
[| eval value=0, category="test", _time=relative_time(now(), "-7d@d")]
| appendpipe
[| eval value=0, category="test", _time=relative_time(now(), "-8d@d")]
| appendpipe
[| eval value=0, category="test", _time=relative_time(now(), "-9d@d")]
| stats count by _time The results of this output 256 results for a single date/time, and others follow with smaller amounts but not counts of 1. If I change it to this: | makeresults
| eval value=0, category="test", _time=relative_time(now(), "-2d@d")
| appendpipe
[| eval value=0, category="test", _time=relative_time(now(), "-1d@d")
| dedup value category _time]
| appendpipe
[| eval value=0, category="test", _time=relative_time(now(), "-2d@d")
| dedup value category _time]
| appendpipe
[| eval value=0, category="test", _time=relative_time(now(), "-3d@d")
| dedup value category _time]
| appendpipe
[| eval value=0, category="test", _time=relative_time(now(), "-4d@d")
| dedup value category _time]
| appendpipe
[| eval value=0, category="test", _time=relative_time(now(), "-5d@d")
| dedup value category _time]
| appendpipe
[| eval value=0, category="test", _time=relative_time(now(), "-6d@d")
| dedup value category _time]
| appendpipe
[| eval value=0, category="test", _time=relative_time(now(), "-7d@d")
| dedup value category _time]
| appendpipe
[| eval value=0, category="test", _time=relative_time(now(), "-8d@d")
| dedup value category _time]
| appendpipe
[| eval value=0, category="test", _time=relative_time(now(), "-9d@d")
| dedup value category _time]
| stats count by _time Every row has a single count except for one, which makes sense given how this is written. I can move forward with this, but now I would like to know why this happens.
... View more