Thanks for the answer, it did the trick. I've adjusted the search as:
`event_sources`
| fillnull
| eval Type=if(Keywords=="Audit Success",Keywords, Type)
| eval Type=if(Keywords=="Audit Failure",Keywords, Type)
| search ((Type="Error" OR Type="Warning") OR (Type="Denial" OR Type="Audit Failure"))
| stats earliest(_time) as First latest(_time) as Last max(Message) as Sample_Message count by host, EventCode, SourceName, Type
| eval First=strftime(First,"%x %X")
| eval Last=strftime(Last,"%x %X")
| sort -count host, EventCode, SourceName, Type
| rename EventCode as "EventId"
| table host,EventCode,SourceName,Type,First,Last,Sample_Message,count
and the date is shown in the report as expected.
... View more