Answer by warren for Splunk: Group by certain entry in log file

Add a by clause to your timechart:

source="/log/ABCD/cABCDXYZ/xyz.log" doSomeTasks
| timechart partial=f span=1h count as "#XYZ doSomeTasks" by taskType
| fillnull

from User warren – Stack Overflow https://stackoverflow.com/questions/64803118/splunk-group-by-certain-entry-in-log-file/64806445#64806445
via IFTTT