# How to translate my sql query into es-sql?

**URL:** <https://discuss.elastic.co/t/how-to-translate-my-sql-query-into-es-sql/308890>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-sql\
**Created:** [July 5, 2022, 9:57am UTC](https://discuss.elastic.co/t/how-to-translate-my-sql-query-into-es-sql/308890 "2022-07-05T09:57:35Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![josephLiu](https://avatars.discourse-cdn.com/v4/letter/j/5f9b8f/32.png) [@josephLiu](https://discuss.elastic.co/u/josephLiu)\
**Post date:** [July 5, 2022, 9:57am UTC](https://discuss.elastic.co/t/how-to-translate-my-sql-query-into-es-sql/308890/1 "2022-07-05T09:57:35Z")

</div>

I want to query the data I need  
In SQL Server I can query like this

select UniqueAuditRecord from dbo.kibanaLog  
group by UniqueAuditRecord having count(\*) =1  
and MAX(timestamp) \<(select max(timestamp) from dbo.kibanaLog where src = 'RS')

But it doesn't seem to work that way in ES,  
I looked up the es documentation ，es don't support complex sub-select  
Is there any other way?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 2, 2022, 9:58am UTC](https://discuss.elastic.co/t/how-to-translate-my-sql-query-into-es-sql/308890/2 "2022-08-02T09:58:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
