# How to work around ES|QL lack of support for unique results

**URL:** https://discuss.elastic.co/t/how-to-work-around-es-ql-lack-of-support-for-unique-results/370172
**Category:** Kibana
**Tags:** discover
**Created:** [November 7, 2024, 3:16pm UTC](https://discuss.elastic.co/t/how-to-work-around-es-ql-lack-of-support-for-unique-results/370172 "2024-11-07T15:16:29Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![pjmlp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pjmlp/32/139018_2.png) [@pjmlp](https://discuss.elastic.co/u/pjmlp)
#### Post date: [November 7, 2024, 3:16pm UTC](https://discuss.elastic.co/t/how-to-work-around-es-ql-lack-of-support-for-unique-results/370172/1 "2024-11-07T15:16:29Z")

</div>

Hi everyone,

I am doing my first steps with analysing reports on Kibana, and after several hours I keep failing to find a way to produce unique results with ES|QL, or KQL as alternative.

It seems to me that it is rather strange that such a common case requires exporting the data into CSV, for handling with external tooling.

If this is documented, it doesn't seem to be easy to spot.

Regards, and thanks in advance,  
Paulo Pinto

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [November 8, 2024, 2:57am UTC](https://discuss.elastic.co/t/how-to-work-around-es-ql-lack-of-support-for-unique-results/370172/2 "2024-11-08T02:57:20Z")

</div>

Hi @pjmlp Welcome to the community.

Apologies not exactly sure what you are trying to accomplish.

The best suggestion I have is to provide a simple example of what you are trying to do.

A couple sample documents and sample results.

Then perhaps we can help

---

<div class="post-metadata">

### Author: ![pjmlp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pjmlp/32/139018_2.png) [@pjmlp](https://discuss.elastic.co/u/pjmlp)
#### Post date: [November 8, 2024, 11:38am UTC](https://discuss.elastic.co/t/how-to-work-around-es-ql-lack-of-support-for-unique-results/370172/3 "2024-11-08T11:38:25Z")

</div>

Hi @stephenb thanks for jumping in,

basically I want to duplicate the same functionality like SQL DISTINCT kind of approach,

So lets say I have,

```auto
from logs-*-*
| where ip.dst is not null and @environment == "Prod" and @type == "traffic.vpc"
| keep ip.dst, port.dst
| sort ip.dst, port.dst
| limit 10000

```

How do I remove the duplicate entries from the result set without having to export into a CSV file to perform that?

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [November 8, 2024, 12:15pm UTC](https://discuss.elastic.co/t/how-to-work-around-es-ql-lack-of-support-for-unique-results/370172/4 "2024-11-08T12:15:15Z")

</div>

Not sure if there are a better way because the examples in the documentation are pretty basic, but what I normally do is to use a stats to get the last timestamp

In your case would be something like this, the `stats` line would get the last event for each combination of ip.dst and port.dst, which would result in unique entries.

```auto
from logs-*-*
| where ip.dst is not null and @environment == "Prod" and @type == "traffic.vpc"
| stats timestamp = MAX(@timestamp) by ip.dst, port.dst
| keep ip.dst, port.dst
| sort ip.dst, port.dst
| limit 10000

```

---

<div class="post-metadata">

### Author: ![pjmlp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pjmlp/32/139018_2.png) [@pjmlp](https://discuss.elastic.co/u/pjmlp)
#### Post date: [November 8, 2024, 2:14pm UTC](https://discuss.elastic.co/t/how-to-work-around-es-ql-lack-of-support-for-unique-results/370172/5 "2024-11-08T14:14:29Z")

</div>

Thanks, it seems to do the trick, a bit hacky but better than the whole export to CSV step.

I guess it will have to do.
