# Lucene query unique values

**URL:** https://discuss.elastic.co/t/lucene-query-unique-values/229057
**Category:** Kibana
**Tags:** canvas
**Created:** [April 21, 2020, 1:41pm UTC](https://discuss.elastic.co/t/lucene-query-unique-values/229057 "2020-04-21T13:41:20Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![Robin020](https://avatars.discourse-cdn.com/v4/letter/r/71c47a/32.png) [@Robin020](https://discuss.elastic.co/u/Robin020)
#### Post date: [April 21, 2020, 1:41pm UTC](https://discuss.elastic.co/t/lucene-query-unique-values/229057/1 "2020-04-21T13:41:20Z")

</div>

Hi,

I am working in Kibana Canvas and have a datatable with a Lucene query filter.  
Now, I only need a lucene query filter which only shows unique values.  
Does somebody know the syntax?

---

<div class="post-metadata">

### Author: ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)
#### Post date: [April 22, 2020, 3:34pm UTC](https://discuss.elastic.co/t/lucene-query-unique-values/229057/2 "2020-04-22T15:34:51Z")

</div>

I don't think you can do this using Lucene, but you can do it using ES SQL which is supported in Canvas. I would recommend using that instead.

---

<div class="post-metadata">

### Author: ![Robin020](https://avatars.discourse-cdn.com/v4/letter/r/71c47a/32.png) [@Robin020](https://discuss.elastic.co/u/Robin020)
#### Post date: [April 22, 2020, 3:46pm UTC](https://discuss.elastic.co/t/lucene-query-unique-values/229057/3 "2020-04-22T15:46:47Z")

</div>

When I use ES SQL and use specific `SQL select distinct` I got the message that Distinct is not supported...  
How should I do this?

---

<div class="post-metadata">

### Author: ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)
#### Post date: [April 22, 2020, 3:59pm UTC](https://discuss.elastic.co/t/lucene-query-unique-values/229057/4 "2020-04-22T15:59:52Z")

</div>

Right, but you can use GROUP BY.

---

<div class="post-metadata">

### Author: ![Robin020](https://avatars.discourse-cdn.com/v4/letter/r/71c47a/32.png) [@Robin020](https://discuss.elastic.co/u/Robin020)
#### Post date: [April 23, 2020, 8:41am UTC](https://discuss.elastic.co/t/lucene-query-unique-values/229057/5 "2020-04-23T08:41:42Z")

</div>

When I use this, it works but with duplicates:

```
SELECT url.domain, summary.up 
FROM "heartbeat*" 
WHERE url.domain 
LIKE '%<DOMAIN>'

```

When I add GROUP BY, I got a parse error:

> Whoops! Expression failed
> 
> Expression failed with the message:
> 
> [essql] \> Unexpected error from Elasticsearch: [verification\_exception] Found 1 problem(s) line 1:20: Cannot use non-grouped column [summary.up], expected [url.domain]

This is the SQL code:

```
SELECT url.domain, summary.up 
FROM "heartbeat*"
WHERE url.domain 
LIKE '%<DOMAIN>'
GROUP BY url.domain

```

---

<div class="post-metadata">

### Author: ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)
#### Post date: [April 23, 2020, 2:47pm UTC](https://discuss.elastic.co/t/lucene-query-unique-values/229057/6 "2020-04-23T14:47:19Z")

</div>

The error message is explaining that you need to add `summary.up` to your GROUP BY: `GROUP BY url.domain, summary.up`

---

<div class="post-metadata">

### Author: ![Robin020](https://avatars.discourse-cdn.com/v4/letter/r/71c47a/32.png) [@Robin020](https://discuss.elastic.co/u/Robin020)
#### Post date: [April 24, 2020, 7:51am UTC](https://discuss.elastic.co/t/lucene-query-unique-values/229057/7 "2020-04-24T07:51:13Z")

</div>

Ok, tnx.  
With doing that, I got still duplicates but that's because summary.up could have 0 or 1.  
Because of that, I try to add a time range. I only like to see the information from now - 11 seconds back. This would remove the duplicates because every 10 seconds heartbeat with do his checks.

I tried this:  
`AND "@timestamp" BETWEEN NOW() - INTERVAL 10 SECONDS`

But it doesn't work how I want it. Have you any suggestions?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 22, 2020, 8:02am UTC](https://discuss.elastic.co/t/lucene-query-unique-values/229057/8 "2020-05-22T08:02:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
