The original signatures lay back quite some time, so i wanted to avoid having to do search such a large interval.
Additionally i would not really see the logic being applicable to a timechart.
Say i want to use the signatures of one day 2 years ago as my reference point and i want to compare if all the different objects had their original signature in the last week, binned daywise and by "object_name".
If you unterstand want i am trying to say.
Anyway my solution for now is
index=my_index name=* | stats latest(Signatur) as sig_c by name
search index=my_index earliest="11/4/2019:08:00:00" latest="11/4/2019:18:00:00" name=*| stats latest(Signatur) as sig_o by name
| eval id = if(sig_o==sig_c, "iO", "niO")| table name id
And for the timechart
index=my_index name="001"| timechart span=1d latest(Signatur) as sig_c
search index=my_index earliest="11/4/2020:08:00:00" latest="11/4/2020:10:00:00" name="001"| stats latest(Signatur) as sig_o
| filldown sig_o
| eval id = if(sig_o==sig_c, 1, 0)| timechart span=1d values(id) as "iO/niO"
But this does not support the desired groub by name yet.