Thank you for your response. I need to add another column from the same index ('index="*appevent" Type="*splunk" ). Column name is 'Type'. My question is how to add column 'Type' with the existing query? Expecting output- | makeresults count=1
| addinfo
| eval days=mvrange(info_min_time, info_max_time, "1d")
| mvexpand days
| eval _time=days, count=0
| append [ search index="*appevent" Type="*splunk"
| bucket _time span=day
| stats count by _time ]
| stats max(count) as Total by _time
| eval "New_Date"=strftime(_time,"%Y-%m-%d")
| table "New_Date" "Total"
... View more