<search string>
| bucket _time span=1h
| stats dc(Serial) as dcSerial, dc(otherserial) as dcOtherSerial by _time
| bucket _time span=1d
| eval Processedtime=strptime(_time,"%s")
| eventstats max(dcSerial) avg(dcSerial) max(dcOtherSerial) avg(dcOtherSerial) by Processedtime
| where as_you_like
use eventstats not stats
... View more