Hi @ITWhisperer Sorry for this new request but maybe you could help me. I'd like to differenciate the empty rows (no log in index) and the rows excluded from the lookup Example : Considering the search period 18/03/2022 00:00:00 => 18/03/2022 01:00:00 In my lookup, the range 18/03/2022 00:00:00<=>18/03/2022 00:10:00 is excluded And there is no log in my source for the period 18/03/2022 00:25:00<=>18/03/2022 01:00:00 I tried this my_index [|inputlookup my_lookup.csv | eval start=strptime(Debut,"%Y-%m-%d %H:%M:%S") | eval end=strptime(Fin,"%Y-%m-%d %H:%M:%S") | sort 0 end | addinfo | where end > info_min_time AND start < info_max_time | append [| makeresults | fields - _time | addinfo | rename info_max_time as start | fields start] | streamstats values(end) as earliest window=1 current=f | eval latest=if(isnull(end), if(earliest > start, null(), start), start) | eval earliest=if(isnull(earliest), if(start < info_min_time, null(), info_min_time), earliest) | where isnotnull(earliest) AND isnotnull(latest) | appendpipe [ stats count | where count=0 | addinfo | rename info_min_time as earliest | rename info_max_time as latest] | fields earliest latest] | timechart span=5m values(URI) as URI sum(NB) as nb avg(DUR) as DUR | fillnull value=NO_LOG And here is the result. Problem : I don't want the 2 first rows to be identified as NO_LOG I tried to identify the "NO_LOG" rows before the lookup exclusion like this my_index | timechart span=5m values(URI) as URI sum(NB) as nb avg(DUR) as DUR | fillnull value=NO_LOG [|inputlookup my_lookup.csv | eval start=strptime(Debut,"%Y-%m-%d %H:%M:%S") | eval end=strptime(Fin,"%Y-%m-%d %H:%M:%S") | sort 0 end | addinfo | where end > info_min_time AND start < info_max_time | append [| makeresults | fields - _time | addinfo | rename info_max_time as start | fields start] | streamstats values(end) as earliest window=1 current=f | eval latest=if(isnull(end), if(earliest > start, null(), start), start) | eval earliest=if(isnull(earliest), if(start < info_min_time, null(), info_min_time), earliest) | where isnotnull(earliest) AND isnotnull(latest) | appendpipe [ stats count | where count=0 | addinfo | rename info_min_time as earliest | rename info_max_time as latest] | fields earliest latest] but I got an error : Error in 'fillnull' command: Invalid argument: 'earliest=1647558000.000' I hope it's clear Thanks in advance
... View more