@ITWhisperer Could you pls check why this query is not listing all the stats fields in the output index=es sourcetype=alert (alert_name!="*PDM*") | stats earliest(_time) as incident_time, values(severity) as severity, values(action) as action, values(file_type) as file_type, values(exposure) as exposure, values(url) as url, values(device) as device by user,alert_name | eval alert_type=case(like(alert_name,"%pdm%"), "pdm", 1==1, "notpdm") | chart count by user alert_type | where notpdm > 1
... View more