Firstly, since log seems to contain JSON, why not use spath with input=log to extract the fields. Secondly, there is no need to search for your fields equal to "*" (which presumably you are doing to remove events with null values for these fields?), as the dedup will do this for you. Thirdly, perhaps you should consider just converting the start to an epoch time with strptime() as you have already done, then use timechart span=1d Finally, this might have been easier to answer if you had provided some anonymised sample events so we can see what you are working with.
... View more