Hi, Thank you for your help, I tried to workout your recommendation and the query looks like below: index="app_cleo_db" origname="GEAC_Payroll*" | rex "\sorigname=\"GEAC_Payroll\((?<digits>\d+)\)\d{8}_\d{6}\.xml\"" | search origname="*.xml" | eval Date = strftime(_time, "%Y-%m-%d %H:00:00") | eval DateOnly = strftime(_time, "%Y-%m-%d") | transaction DateOnly, origname | timechart span=1h count by DateOnly | eval _time=strftime(_time, "%H:%M:%S") But this is still giving me the time for both the dates if I try to run my query for 2 days : _time 2023-12-02 2023-12-03 00:00:00 0 0 01:00:00 0 0 02:00:00 0 0 03:00:00 0 0 00:00:00 0 0 01:00:00 0 0 02:00:00 0 0 03:00:00 1 0
... View more