I read my data with the inputlookup command and try to count the different occurrences of the field fields.SID as below:
| eval time=relative_time(now(),"-24h")
| eval time=ceil(time)
| table time
| map [ |inputlookup incidents where alert_time > $time$ ]
| join incident_id
[ |inputlookup incident_results ]
| fields fields.SID
| search fields.SID=*
| mvexpand fields.SID
Unfortunately, whatever tricks I do I am always getting several SIDs packed into a single event, see the screenshot below.
How would I split it the way to have each fields.SID in separate row to be able to count it?
I created another question where I rephrased the issue and got the solution below. Therefore i am closing this one.
View solution in original post