This is my search:
eventtype=msad-failed-user-logons (host="*")|fields time,signature,srcip,srchost,srcnthost,srcntdomain,user,LogonType |ip-to-host|fix-localhost|stats count by user,srcnthost,srcip|sort -count|rename user as "Username" srcnthost as "Workstation",srcip as "IP Address" | head 6
@test_qweqwe, you want to plot a timechart then you need _time as one of the fields. Your stats query is removing _time field. Also if you just need count by user over _time, you do not need to worry about other fields. Try the following search. I am expecting your eventtype msad-failed-user-logons gives only failed user logon events.
| timechart count by user