@yuanliu I'm fairly new to Splunk this year. Can you explain what you mean? - "You can still use the fields in statistical functions"
I've tried
Thanks.
That's because at index time (when Splunk ingests data), fields like UserKey_ABC.job1 doesn't exist. They are extracted at search time by some mechanism, but do not exist in indexer.
tstats only operates on indexed fields. You can still use the fields in statistical functions. So, you need to define how you want to see these values, and you cannot use them in groupby.