I'm attempting to run a query and I've run into a really weird situation where if I run a query with "head 10 | fields *" I'm getting results but if I use "stats" with any field it does not return results.
For example, this query is returning the results:
index=main sourcetype=o365:management:activity Field1=Value1
| head 10
| fields *
This is returning no results:
index=main sourcetype=o365:management:activity Field1=Value1
| stats count by _time
Somehow this does work and returns the result
index=main sourcetype=o365:management:activity Field1=Value1
| head 10
| stats count by _time
I've looked into it and did not manage to find similar issues, did anyone see anything similar before?
... View more