Hi @gcusello , if I remove (| dedup computer.pagination.id) I get results all the way back to Sep 25 the day I set up my Splunk with Jamf sourcetype="jamfmodularinput" computer.hardware.os_build="19H2" OR computer.hardware.os_build="18G6032" OR computer.hardware.os_build="17G14033" earliest=-30d@d latest=now | eval computer.hardware.os_build=case(computer.hardware.os_build="19H2","macOS Catalina",computer.hardware.os_build="18G6032","macOS Mojave",computer.hardware.os_build="17G14033","macOS High Sierra") | timechart span=1d count BY computer.hardware.os_build But when I use your search (| eval)I only get one value null, and I don't get separated columns for each macOS build. On the other hand, when I use (| rex) I get the macOS Build separately thank you in advance
... View more