# Latest timestamp in lens table?

**URL:** <https://discuss.elastic.co/t/latest-timestamp-in-lens-table/305333>\
**Category:** Kibana\
**Tags:** lens\
**Created:** [May 21, 2022, 3:19pm UTC](https://discuss.elastic.co/t/latest-timestamp-in-lens-table/305333 "2022-05-21T15:19:01Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![David\_Hodgson](https://avatars.discourse-cdn.com/v4/letter/d/9fc29f/32.png) [@David\_Hodgson](https://discuss.elastic.co/u/David_Hodgson)\
**Post date:** [May 21, 2022, 3:19pm UTC](https://discuss.elastic.co/t/latest-timestamp-in-lens-table/305333/1 "2022-05-21T15:19:01Z")

</div>

I'm trying to create a Lens table in a Dashboard summarising heartbeats, with columns:

- monitor.name,
- monitor.status,
- last\_value(@timestamp, kql='monitor.status:"up"'),
- last\_value(@timestamp, kql='monitor.status:"down"')  
...

and Lens is complaining that @timestamp is of the wrong type. I think it will only work with a numeric field.

Is there a workaround?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 21, 2022, 5:15pm UTC](https://discuss.elastic.co/t/latest-timestamp-in-lens-table/305333/2 "2022-05-21T17:15:15Z")

</div>

@David_Hodgson Welcome to the Community and Nice Use Case! Seems like a useful Table!

> [@David\_Hodgson](#):
>
> Is there a workaround?

Yes! I got one for you ... and @ghudgins I think I perhaps found a bug... (I will put that at the bottom)

Here are the Macro Steps

1. Create a Runtime field for the timestamp that is type `keyword`
2. Then use Last Value Function with the `timestamp_keyword` and filter on `monitor.status`

Create a `timestamp_keyword` field

Here is the code

`emit(doc['@timestamp'].value.toString())`

 ![Screen Shot 2022-05-21 at 10.02.08 AM](https://us1.discourse-cdn.com/elastic/original/3X/9/e/9ebb5851ea26254cf87f3b4d9ce7cd164cd4491b.png)

 ![Screen Shot 2022-05-21 at 8.52.21 AM](https://us1.discourse-cdn.com/elastic/original/3X/0/1/018b771791f2b1fb0dc0c21aab77cbb6db7805bd.png)

Now create the table (I am using `url.domain` because I only have a single monitor but multiple domain but same principle)

 ![Screen Shot 2022-05-21 at 10.08.17 AM](https://us1.discourse-cdn.com/elastic/original/3X/7/0/703d60f8b887723da2027a4b846b07ffbfabd028.png)

Whalluh! Now do the same for `monitor.status : "down"`

Now @ghudgins Here is think is the bug  
If I try to do the same thing as a formula... which I think should work

`last_value(timestamp_keyword, kql='monitor.status : "up" ')`

But it says there is an error return type invalid I would think it should work with a keyword ... but as the OP observed it looks like it only supports numbers but when I do it through the quick function + filter it works

 ![Screen Shot 2022-05-21 at 10.11.46 AM](https://us1.discourse-cdn.com/elastic/original/3X/8/e/8ed23763f4e04f39d2e8118b979f7bca0d55549f.png)

Note Only Numerics .... no `keywords`

 ![Screen Shot 2022-05-21 at 10.12.50 AM](https://us1.discourse-cdn.com/elastic/original/3X/9/f/9fd2155eb07cd8f01d3a3a6667b943f35063e064.png)

---

<div class="post-metadata">

**Author:** ![ghudgins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghudgins/32/138532_2.png) [@ghudgins](https://discuss.elastic.co/u/ghudgins)\
**Post date:** [May 23, 2022, 2:32pm UTC](https://discuss.elastic.co/t/latest-timestamp-in-lens-table/305333/3 "2022-05-23T14:32:07Z")

</div>

i'm not sure if this is a bug. formula can only work when the resulting field is a number guarenteed...so last value on a keyword field would blow up if it's not a number. it works with a quick function becuase those work on non-number fields (no pesky math, just display it!)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 23, 2022, 2:40pm UTC](https://discuss.elastic.co/t/latest-timestamp-in-lens-table/305333/4 "2022-05-23T14:40:01Z")

</div>

Yeah but why does the lastvalue formula only work on a number? It should just be whatever the last value in that field is based on the timestamp ... number keyword. Who cares? It's just the last value based on the timestamp... The math is on the timestamp, not on the field value itself.

---

<div class="post-metadata">

**Author:** ![ghudgins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghudgins/32/138532_2.png) [@ghudgins](https://discuss.elastic.co/u/ghudgins)\
**Post date:** [May 23, 2022, 2:53pm UTC](https://discuss.elastic.co/t/latest-timestamp-in-lens-table/305333/5 "2022-05-23T14:53:55Z")

</div>

8.2 adds date support for last value [[Lens] unable to add last value of date/string field · Issue #104787 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/104787) (in the UI)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 23, 2022, 3:11pm UTC](https://discuss.elastic.co/t/latest-timestamp-in-lens-table/305333/6 "2022-05-23T15:11:44Z")

</div>

@ghudgins Yup that works via Quick Functions and Formula in 8.2 for both timestamps and keywords .. Thanks!

So @David_Hodgson You can use my workaround or upgrade to version 8.2 and last\_value you will work as you expect.

 ![Screen Shot 2022-05-23 at 8.02.54 AM](https://us1.discourse-cdn.com/elastic/original/3X/c/c/cce66294fc36eaac34220ad86c65f6dad222e9ca.png)

 ![Screen Shot 2022-05-23 at 8.03.07 AM](https://us1.discourse-cdn.com/elastic/original/3X/5/1/51fc2fe157286a1c0aae6cbc9d608dacb4dee62f.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 20, 2022, 3:12pm UTC](https://discuss.elastic.co/t/latest-timestamp-in-lens-table/305333/7 "2022-06-20T15:12:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
