Close, but not quite 🙂 Try to understand what you're doing. Firstly, you search for some events with eventtype=heartbeat. Now everything is ok. Of those events some will have more than one eventtype. Then you do | search eventtype=heartbeat Which effectively doesn't do anything at this point since all events you find in the previous step had eventtype=heartbeat. So you pass this stepp with your full set of resulting events of which some have more than one eventtype. Then if you do the timechart by eventtypes of course all your eventtypes will get included in the results What did you do wrong? You did a search in the wrong place. You should have done stats first, so you get results for all eventtypes and _then_ search (in the resulting stats) for wanted eventtypes. eventtype=heartbeat namespace::my-namespace | timechart count by eventtype span=1 | search eventtype=heartbeat
... View more