With the below query I am able to get data as below(first one) and I need to convert it as second box
For the time field I am getting common values and i need to merge and combine them as shown. is there any way to achieve this, I've tried with values() but it is not working
sourcetype=access_combined | eval action = if(isnull(action) OR action="", "unknown", action) | bin _time span=102h |eval Time=strftime(_time,"%Y-%m-%d %H:%M:%S") | stats count as totals by action,Time | sort -Time,action
Have you tried adding
...
| stats values(action) as action, values(totals) as totals by Time
| fields action, Time, totals
Yes, but it's not worked.