The search below doesn't work when i add department in the group by fields in the streamstats commands. It works with any other field but this one. Can someone please give some insight?
index=...
| lookup lookup cn as user OUTPUT department
| reverse
| dedup department application feature time
| streamstats current=f window=1 values(currTotalCount) as prev_count by application feature department
| table department application user display time feature currTotalCount prev_count
The prev_count field is empty when i add the department in the group by fields (streamstats command), otherwise it shows the correct result.
Fixed it by adding global=false