hi, below query is used for the drill down used for my line graph. | savedsearch XYZ | eval Deactivated = strftime(strptime(TO_DATE, "%Y-%m-%d %H:%M:%S.%N"), "%B-%y") | eval Created = strftime(strptime(FROM_DATE, "%Y-%m-%d %H:%M:%S.%N"), "%B-%y") | where $apps$ and $bscode$ and $function$ and $dept$ and $country$ and $emp_type$ | search $usertype|s$ = $monthname|s$ | table Function, BS_ID, APP_NAME, MUID, FIRST_NAME, LAST_NAME, FROM_DATE, TO_DATE, LASTLOGON, COUNTRY, CITY, DEPARTMENT_LONG_NAME, "Business Owner", SDM, "System Owner", "Validation Owner" the above query looks like this in the search panel: | savedsearch hourradata2 | eval Deactivated = strftime(strptime(TO_DATE, "%Y-%m-%d %H:%M:%S.%N"), "%B-%y") | eval Created = strftime(strptime(FROM_DATE, "%Y-%m-%d %H:%M:%S.%N"), "%B-%y") | where like (APP_NAME ,"Managed iMAP Application") and like (BS_ID,"%") and like (Function,"%") and like (DEPARTMENT_LONG_NAME,"%") and like (COUNTRY,"%") and like(EMPLOYEE_TYPE,"%") | search "Active" = "June-23" | table Function, BS_ID, APP_NAME, MUID, FIRST_NAME, LAST_NAME, FROM_DATE, TO_DATE, LASTLOGON, COUNTRY, CITY, DEPARTMENT_LONG_NAME, "Business Owner", SDM, "System Owner", "Validation Owner" if the highlighted one's removed then the query gives result.
... View more