We have 3 different (Active,Closed,Resolved) records for same Incident and we need to retrieve only Active incident record and Incident shouldn't have any other status records such as Closed,Resolved. shashi584_0-1626101590120.png Below query is still showing Active Incident record, however Incident is already in resolved status... index="snow" sourcetype="snow:incident" source="https://dell.service-now.com/" dv_assignment_group = "ITOPS-DCE-SELLER-SUPPORT" dv_u_cim_true="true" | where like(dv_incident_state,"Active") AND NOT like (dv_incident_state,"Resolved") AND NOT like (dv_incident_state,"Closed") | dedup dv_incident_state | stats count by dv_incident_state, dv_number,dv_active
... View more