Hello, Thanks for your response. Here below is my query. | tstats count as per_day_count latest(_time) as LTime_per_day where (index=xxxx earliest=-14d@d latest=now) groupby source _time | bin span=1d _time | lookup data_sources.csv source OUTPUTNEW data_source, Monitor | search Monitor=Yes | eval Last_event_time_per_day=strftime(LTime_per_day,"%b %d,%Y %H:%M:%S %p %Z") | join type=outer data_source [ tstats count latest(_time) as LTime values(sourcetype) as sourcetype where (index=yyyy* OR (index=zzzz sourcetype=*amp*)earliest=-d@d latest=now) groupby source _time | bin span=1d _time | lookup data_sources.csv source OUTPUTNEW data_source Monitor | eval Last_event_time=strftime(LTime,"%b %d,%Y %H:%M:%S %p %Z") | eval status= if(count > 0, "Data Received","NO Data Received") ] | eval Last_event_time=strftime(LTime,"%b %d,%Y %H:%M:%S %p %Z") | table data_source sourcetype count Last_event_time Last_event_time_per_day status per_day_count _time | fillnull value="NO Data Received" status | sort - status | rename count as "Event Count" | sort + sourcetype | fillnull value="-" | streamstats window=7 current=f list(per_day_count) as count1 by data_source | stats latest(per_day_count) as today_count, max(Last_event_time_per_day) as max_time_each_day by _time data_source | sort data_source, -_time and here below is a sample subset returned by the above query: max_time_each_day data_source today_count Sep 15,2021 07:25:01 AM EDT ABC 14503 Sep 14,2021 23:59:51 PM EDT ABC 51570 Sep 13,2021 23:59:57 PM EDT ABC 56331 Sep 12,2021 23:59:59 PM EDT ABC 55717 Sep 11,2021 23:59:51 PM EDT ABC 54480 Sep 10,2021 23:59:49 PM EDT ABC 65367 Sep 09,2021 23:59:59 PM EDT ABC 61999 Sep 08,2021 23:59:57 PM EDT ABC 55405 Sep 07,2021 23:59:51 PM EDT ABC 62327 Sep 06,2021 23:59:48 PM EDT ABC 54137 Sep 05,2021 23:59:56 PM EDT ABC 49224 Sep 04,2021 23:59:54 PM EDT ABC 47783 Sep 03,2021 23:59:52 PM EDT ABC 52699 Sep 02,2021 23:59:53 PM EDT ABC 70145 Sep 01,2021 23:59:57 PM EDT ABC 79071 Sep 14,2021 10:05:16 AM EDT XYZ 21 Sep 13,2021 10:32:58 AM EDT XYZ 23 Sep 10,2021 11:30:07 AM EDT XYZ 22 Sep 09,2021 09:51:28 AM EDT XYZ 19 Sep 08,2021 09:56:16 AM EDT XYZ 19 Sep 05,2021 04:32:44 AM EDT XYZ 19 Sep 02,2021 10:03:06 AM EDT XYZ 19 Sep 01,2021 04:32:54 AM EDT XYZ 19 Sep 15,2021 04:32:00 AM EDT PQR 229 Sep 14,2021 04:31:59 AM EDT PQR 268 Sep 13,2021 04:32:03 AM EDT PQR 302 Sep 12,2021 04:31:59 AM EDT PQR 302 Sep 11,2021 04:32:15 AM EDT PQR 297 Sep 10,2021 04:32:00 AM EDT PQR 305 Sep 09,2021 04:32:04 AM EDT PQR 267 Sep 08,2021 04:32:02 AM EDT PQR 267 Sep 07,2021 04:32:12 AM EDT PQR 305 Sep 06,2021 04:32:01 AM EDT PQR 305 Sep 05,2021 04:31:53 AM EDT PQR 195 Sep 04,2021 04:31:52 AM EDT PQR 157 Sep 03,2021 04:32:01 AM EDT PQR 267 Sep 02,2021 04:31:59 AM EDT PQR 157 Sep 01,2021 04:32:53 AM EDT PQR 305 Sep 14,2021 10:05:15 AM EDT DST 103 Sep 13,2021 10:33:00 AM EDT DST 109 Sep 10,2021 11:30:07 AM EDT DST 106 Sep 09,2021 04:31:55 AM EDT DST 105 Sep 08,2021 09:51:06 AM EDT DST 36 Sep 07,2021 15:44:18 PM EDT DST 71 Sep 02,2021 04:31:59 AM EDT DST 105 Sep 01,2021 16:44:02 PM EDT DST 105 My requirement is that to fill the time gaps for data_source "XYZ" and "DST" and for these two data sources I should have today_count=0 for those gaps. Thanks in advance. Regards,
... View more