# Kibana Query for Max Date?

**URL:** <https://discuss.elastic.co/t/kibana-query-for-max-date/32804>\
**Category:** Kibana\
**Created:** [October 22, 2015, 7:31pm UTC](https://discuss.elastic.co/t/kibana-query-for-max-date/32804 "2015-10-22T19:31:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tmo\_bgc](https://avatars.discourse-cdn.com/v4/letter/t/4491bb/32.png) [@tmo\_bgc](https://discuss.elastic.co/u/tmo_bgc)\
**Post date:** [October 22, 2015, 7:31pm UTC](https://discuss.elastic.co/t/kibana-query-for-max-date/32804/1 "2015-10-22T19:31:31Z")

</div>

Hi,

Using Logstash I have JSON docs that gets stored into Elastic Search every minute with the most current timestamp, and with c1 being the count of rows returned by a SQL Query.

{  
"c1" =\> 0,  
"@version" =\> "1",  
"@timestamp" =\> "2015-10-22T19:10:00.258Z",  
"type" =\> "testuser1-counts",  
"username" =\> "testuser1"  
}

Using Kibana and the following Query string, i'm able to fetch all the JSON docs persisted into Elastic search associated with the type testuser1-counts.

type:"testuser1-counts"

However what Query string can I use in Kibana to fetch the one JSON doc with the latest timestamp, that way I have access to the latest c1 count?

Many thanks,  
Tony

---

<div class="post-metadata">

**Author:** ![tmo\_bgc](https://avatars.discourse-cdn.com/v4/letter/t/4491bb/32.png) [@tmo\_bgc](https://discuss.elastic.co/u/tmo_bgc)\
**Post date:** [October 23, 2015, 2:10pm UTC](https://discuss.elastic.co/t/kibana-query-for-max-date/32804/2 "2015-10-23T14:10:20Z")

</div>

I'm quite new to Kibana and Lucene queries  
Is what I described even possible? Anyone?

thanks,  
Tony

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [October 24, 2015, 2:18pm UTC](https://discuss.elastic.co/t/kibana-query-for-max-date/32804/3 "2015-10-24T14:18:31Z")

</div>

Kibana query string is based on [Lucene query syntax](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html), or you can also use the "[filters](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-filters.html)" part of Elasticsearch Query DSL. Neither would give you the ability to run a function and determine a "max" value, for that you need aggregations. In Kibana 4, aggregations are exposed using the vis builder, so here is one way to display a max date.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/6/61386175bb4d05b908ab04a34ed7bee5a8a16115.png)

Unfortunately, since at this time there is no way to filter for documents with max date, there is no way to display a value at max date. We are tracking an enhancement for that: [https://github.com/elastic/kibana/issues/678](https://github.com/elastic/kibana/issues/678)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:10pm UTC](https://discuss.elastic.co/t/kibana-query-for-max-date/32804/4 "2017-07-06T14:10:46Z")

</div>


