# Query to get latest document per minute

**URL:** <https://discuss.elastic.co/t/query-to-get-latest-document-per-minute/308452>\
**Category:** Kibana\
**Tags:** kql-kibana-query-language\
**Created:** [June 29, 2022, 10:18am UTC](https://discuss.elastic.co/t/query-to-get-latest-document-per-minute/308452 "2022-06-29T10:18:13Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yair\_Gofen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yair_gofen/32/107626_2.png) [@Yair\_Gofen](https://discuss.elastic.co/u/Yair_Gofen)\
**Post date:** [June 29, 2022, 10:18am UTC](https://discuss.elastic.co/t/query-to-get-latest-document-per-minute/308452/1 "2022-06-29T10:18:14Z")

</div>

Hi,  
I am looking for a way to filter documents according to their timestamp, and get only latest document per 1 min.  
for example, i have 10 document indexed per minute, and i want to query over time range of 10 minutes and get only 10 documents (index has 100 but i need only the last one per minute).  
is there any way to accomplish that with KQL syntax?  
the reason for using KQL is that i want to implement the filter from map layer context, and it seems to only support KQL syntax.

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [June 29, 2022, 3:32pm UTC](https://discuss.elastic.co/t/query-to-get-latest-document-per-minute/308452/2 "2022-06-29T15:32:37Z")

</div>

`kql` is just for query documents. To extract last documents per minutes, you need aggregation. It couldn't be accomplished by kql.

One possible option is to add "minute" field to the index somehow (you can use [runtime fields](https://www.elastic.co/guide/en/elasticsearch/reference/current/runtime-retrieving-fields.html#runtime-define-field-dayofweek)) and use [latest transform](https://www.elastic.co/guide/en/elasticsearch/reference/current/transforms.html) to create another index which contains only last document per minute.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 27, 2022, 3:32pm UTC](https://discuss.elastic.co/t/query-to-get-latest-document-per-minute/308452/3 "2022-07-27T15:32:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
