# \#esql

**URL:** https://discuss.elastic.co/tag/esql/149.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [Time picker in ES|QL query - esql](https://discuss.elastic.co/t/time-picker-in-es-ql-query-esql/390631)

<div class="topic-metadata">

**Author:** [@dot-mike](https://discuss.elastic.co/u/dot-mike)\
**Replies:** 2\
**Last updated:** [September 25, 2026, 1:55pm UTC](https://discuss.elastic.co/t/time-picker-in-es-ql-query-esql/390631 "2026-09-25T13:55:30Z")

</div>

Hi community, I was wondering about a weird behaviour that might catch some people off-guard. How does the time picker affect ES|QL searches? For example the following query implies a 24-hour search, but yet the data d…

---

## [Field formatters in ES|QL table panels](https://discuss.elastic.co/t/field-formatters-in-es-ql-table-panels/390418)

<div class="topic-metadata">

**Author:** [@tallakh](https://discuss.elastic.co/u/tallakh)\
**Replies:** 1\
**Last updated:** [September 23, 2026, 8:07am UTC](https://discuss.elastic.co/t/field-formatters-in-es-ql-table-panels/390418 "2026-09-23T08:07:19Z")

</div>

Hi! We have started to use ES|QL a lot in our Kibana dashboards, and I love the flexibility it brings! One of the few missing features compared to Lens table panels is to set formatting on a text/keyword field. F ex a l…

---

## [How to filter an ESQL dashboard on a field in the index being looked up on](https://discuss.elastic.co/t/how-to-filter-an-esql-dashboard-on-a-field-in-the-index-being-looked-up-on/386052)

<div class="topic-metadata">

**Author:** [@TSlump](https://discuss.elastic.co/u/TSlump)\
**Replies:** 3\
**Last updated:** [April 28, 2026, 10:07am UTC](https://discuss.elastic.co/t/how-to-filter-an-esql-dashboard-on-a-field-in-the-index-being-looked-up-on/386052 "2026-04-28T10:07:39Z")

</div>

Hi, I'm having trouble finding a nice intuitive way to filter an ESQL dashboard. Any ideas would be greatly appreciated ! I have two indices: buildings and rooms, where each room has a building Id. On the dashboard I ha…

---

## [ES|QL LOOKUP JOIN between fields containing a list of values](https://discuss.elastic.co/t/es-ql-lookup-join-between-fields-containing-a-list-of-values/385960)

<div class="topic-metadata">

**Author:** [@smyttie](https://discuss.elastic.co/u/smyttie)\
**Replies:** 2\
**Last updated:** [April 21, 2026, 4:58am UTC](https://discuss.elastic.co/t/es-ql-lookup-join-between-fields-containing-a-list-of-values/385960 "2026-04-21T04:58:54Z")

</div>

Hi all, creating a LOOKUP JOIN query is working fine, but I am not getting results when I have to do it between 2 fields containing a list of values. For example : main index field = "sizes" : \["S", "M"\] lookup index…

---

## [Refer to value lists in ES|QL?](https://discuss.elastic.co/t/refer-to-value-lists-in-es-ql/384135)

<div class="topic-metadata">

**Author:** [@alyx](https://discuss.elastic.co/u/alyx)\
**Replies:** 1\
**Last updated:** [April 17, 2026, 6:37pm UTC](https://discuss.elastic.co/t/refer-to-value-lists-in-es-ql/384135 "2026-04-17T18:37:21Z")

</div>

Hi everyone! Trying to migrate from other SIEM platforms. One question is, is it possible to define some lists and refer to them across different rules? Like WHERE source.ip IN ${some\_defined\_list}? I tried to use valu…

---

## [Getting LAST record in aggr in ES|QL](https://discuss.elastic.co/t/getting-last-record-in-aggr-in-es-ql/372903)

<div class="topic-metadata">

**Author:** [@jfsardon](https://discuss.elastic.co/u/jfsardon)\
**Replies:** 11\
**Last updated:** [April 16, 2026, 6:33pm UTC](https://discuss.elastic.co/t/getting-last-record-in-aggr-in-es-ql/372903 "2026-04-16T18:33:40Z")

</div>

Is there an simple way to get the last value of a field (@timestamp sorted) for each customer, hostname, etc.. For example : select logs-myindex-xxx | SORT (@timestamp) | STATS LAST (maxsize) BY customer, hostname... b…

---

## [Lookup join and visualization on that join](https://discuss.elastic.co/t/lookup-join-and-visualization-on-that-join/385464)

<div class="topic-metadata">

**Author:** [@jai2](https://discuss.elastic.co/u/jai2)\
**Replies:** 5\
**Last updated:** [March 18, 2026, 10:36am UTC](https://discuss.elastic.co/t/lookup-join-and-visualization-on-that-join/385464 "2026-03-18T10:36:45Z")

</div>

Consider the following, I have populated 2 indices, both have a task\_id field and I want to join these 2 indices on task\_id to create a dashboard in Kibana. Firstly, I cannot create a data view out of a lookup join. I …

---

## [Can I use ESQL Lookup Join to match fields with different names?](https://discuss.elastic.co/t/can-i-use-esql-lookup-join-to-match-fields-with-different-names/385324)

<div class="topic-metadata">

**Author:** [@TSlump](https://discuss.elastic.co/u/TSlump)\
**Replies:** 7\
**Last updated:** [March 4, 2026, 1:33pm UTC](https://discuss.elastic.co/t/can-i-use-esql-lookup-join-to-match-fields-with-different-names/385324 "2026-03-04T13:33:03Z")

</div>

Hi, I have two indices with matching fields that I want to use for an ESQL Lookup Join, however, the fields in each index have different names. Am I still able to use a lookup join? As an example, I have a ‘customers’ …

---

## [ES|QL Invoke-WebRequest how to](https://discuss.elastic.co/t/es-ql-invoke-webrequest-how-to/384848)

<div class="topic-metadata">

**Author:** [@a11](https://discuss.elastic.co/u/a11)\
**Replies:** 1\
**Last updated:** [February 5, 2026, 3:24pm UTC](https://discuss.elastic.co/t/es-ql-invoke-webrequest-how-to/384848 "2026-02-05T15:24:19Z")

</div>

Hello, I’m trying to send a webrequest with a powershell script: { "query": """ FROM packetbeat-tls | WHERE dnsdomain.keyword == "%domain%" AND @timestamp \> NOW() - 7days | KEEP host.name.keyword, source.ip.keyword …

---

## [Further enhance TOP ES|QL function please](https://discuss.elastic.co/t/further-enhance-top-es-ql-function-please/384898)

<div class="topic-metadata">

**Author:** [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Replies:** 0\
**Last updated:** [February 3, 2026, 7:50pm UTC](https://discuss.elastic.co/t/further-enhance-top-es-ql-function-please/384898 "2026-02-03T19:50:22Z")

</div>

Now that 9.3.0 is out, I notice this added (and very useful) ES|QL feature: Support extra field (outputField) in TOP function. Values of outputField will be returned instead of values of field , as discussed here and t…

---

## [ES|QL: How to count latest status per key without transform](https://discuss.elastic.co/t/es-ql-how-to-count-latest-status-per-key-without-transform/384430)

<div class="topic-metadata">

**Author:** [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Replies:** 1\
**Last updated:** [January 8, 2026, 8:20am UTC](https://discuss.elastic.co/t/es-ql-how-to-count-latest-status-per-key-without-transform/384430 "2026-01-08T08:20:14Z")

</div>

Hello Team, I am trying to compute metrics based only on the latest record per key using ES|QL in 9.x version? I have a time-series index where each entity (e.g. trainnumber) emits multiple events over time and I want …

---

## [Dec 18th, 2025: \[EN\] Using ES|QL with dense\_vector fields](https://discuss.elastic.co/t/dec-18th-2025-en-using-es-ql-with-dense-vector-fields/384024)

<div class="topic-metadata">

**Author:** [@Carlos\_D](https://discuss.elastic.co/u/Carlos_D)\
**Replies:** 0\
**Last updated:** [December 18, 2025, 8:00am UTC](https://discuss.elastic.co/t/dec-18th-2025-en-using-es-ql-with-dense-vector-fields/384024 "2025-12-18T08:00:18Z")

</div>

Este artículo está disponible en Español. Vector Search with ES|QL Today we're unwrapping one of the most exciting additions to ES|QL: native support for dense vector fields, and the functions to search them: The KNN …

---

## [Dec 18th, 2025: \[ES\] Búsqueda Vectorial con ES|QL](https://discuss.elastic.co/t/dec-18th-2025-es-busqueda-vectorial-con-es-ql/384026)

<div class="topic-metadata">

**Author:** [@Carlos\_D](https://discuss.elastic.co/u/Carlos_D)\
**Replies:** 0\
**Last updated:** [December 18, 2025, 8:00am UTC](https://discuss.elastic.co/t/dec-18th-2025-es-busqueda-vectorial-con-es-ql/384026 "2025-12-18T08:00:18Z")

</div>

This post is also available in English. Búsqueda Vectorial con ES|QL Hoy descubrimos una de las incorporaciones más interesantes en ES|QL: Soporte nativo para campos dense\_vector, y las funciones para buscar en ellos…

---

## [ES|QL dashboard table visualization displays time fields in UTC time zone](https://discuss.elastic.co/t/es-ql-dashboard-table-visualization-displays-time-fields-in-utc-time-zone/382245)

<div class="topic-metadata">

**Author:** [@allatrue](https://discuss.elastic.co/u/allatrue)\
**Replies:** 5\
**Last updated:** [November 25, 2025, 2:00pm UTC](https://discuss.elastic.co/t/es-ql-dashboard-table-visualization-displays-time-fields-in-utc-time-zone/382245 "2025-11-25T14:00:30Z")

</div>

Hello everyone, is there a way to make ES|QL visualization to display time fields in local time zone, like Lens it does? Discover converts times automatically to local time, as well as Lens dashboard visualizations. Bu…

---

## [Need help with simple agregation](https://discuss.elastic.co/t/need-help-with-simple-agregation/383274)

<div class="topic-metadata">

**Author:** [@marjue](https://discuss.elastic.co/u/marjue)\
**Replies:** 4\
**Last updated:** [November 7, 2025, 4:21am UTC](https://discuss.elastic.co/t/need-help-with-simple-agregation/383274 "2025-11-07T04:21:41Z")

</div>

Hello I need help in a simple case but I’m too stupid. There is an index with simple monitoring data. The main fields are: service\_name (text) service\_status (text) service\_time (date) Every 5 minutes a new state f…

---

## [ES|QL Basic Help](https://discuss.elastic.co/t/es-ql-basic-help/383107)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [October 30, 2025, 6:21pm UTC](https://discuss.elastic.co/t/es-ql-basic-help/383107 "2025-10-30T18:21:15Z")

</div>

Hello, I did a STATS count = COUNT\_DISTINCT(event.outcome) by host.name. And it works, the only issue I wish I could keep the metadata information about the host? Is there a way to do this??

---

## [ES|QL date histogram?](https://discuss.elastic.co/t/es-ql-date-histogram/383029)

<div class="topic-metadata">

**Author:** [@kmp](https://discuss.elastic.co/u/kmp)\
**Replies:** 4\
**Last updated:** [October 28, 2025, 3:32pm UTC](https://discuss.elastic.co/t/es-ql-date-histogram/383029 "2025-10-28T15:32:44Z")

</div>

I’m really trying to start to use ES|QL… About six months ago, I generated some queries (saved search sessions) and was wondering why (unlike the Classic search) there was no date histogram displayed. I was playing aro…

---

## [ES|QL Drill Down in Kibana](https://discuss.elastic.co/t/es-ql-drill-down-in-kibana/376008)

<div class="topic-metadata">

**Author:** [@sai\_ravi\_shankar](https://discuss.elastic.co/u/sai_ravi_shankar)\
**Replies:** 2\
**Last updated:** [September 9, 2025, 6:28am UTC](https://discuss.elastic.co/t/es-ql-drill-down-in-kibana/376008 "2025-09-09T06:28:08Z")

</div>

Hi Team, I Have created a drill down url for a field under the data view in Kibana, When I create a table visualization using ES|QL. The field value is not showing as hyper link whereas if created the table visualizati…

---

## [Python: ImportError: cannot import name 'E' from 'elasticsearch.esql'](https://discuss.elastic.co/t/python-importerror-cannot-import-name-e-from-elasticsearch-esql/381204)

<div class="topic-metadata">

**Author:** [@peter9](https://discuss.elastic.co/u/peter9)\
**Replies:** 3\
**Last updated:** [August 29, 2025, 1:02pm UTC](https://discuss.elastic.co/t/python-importerror-cannot-import-name-e-from-elasticsearch-esql/381204 "2025-08-29T13:02:01Z")

</div>

I am reading the docs at ES|QL Query Builder | Python There are examples that start with: from elasticsearch.esql import ESQL, E When I try these, I get: ImportError: cannot import name 'E' from 'elasticsearch.esql' …

---

## [How to query a sum and it's percentage in the same query?](https://discuss.elastic.co/t/how-to-query-a-sum-and-its-percentage-in-the-same-query/381229)

<div class="topic-metadata">

**Author:** [@khat33b](https://discuss.elastic.co/u/khat33b)\
**Replies:** 4\
**Last updated:** [August 22, 2025, 2:49pm UTC](https://discuss.elastic.co/t/how-to-query-a-sum-and-its-percentage-in-the-same-query/381229 "2025-08-22T14:49:44Z")

</div>

I am writing an ES|QL to find out the sum and of a field grouped by another field and also it’s percentage by other sums of that field. How do I write the query? FROM test\_index | WHERE start\_time \>= DATE\_PARSE("yyyy-M…

---

## [Result from ES|QL differs from result of regular search](https://discuss.elastic.co/t/result-from-es-ql-differs-from-result-of-regular-search/381123)

<div class="topic-metadata">

**Author:** [@peter9](https://discuss.elastic.co/u/peter9)\
**Replies:** 8\
**Last updated:** [August 19, 2025, 6:27pm UTC](https://discuss.elastic.co/t/result-from-es-ql-differs-from-result-of-regular-search/381123 "2025-08-19T18:27:53Z")

</div>

This regular query: GET /twitter20230601-times/\_search { "\_source": \["counts"\] } results: { "took": 0, "timed\_out": false, "\_shards": { "total": 1, "successful": 1, "skipped": 0, "failed": 0 …

---

## [ESQL beginner grouping question](https://discuss.elastic.co/t/esql-beginner-grouping-question/381054)

<div class="topic-metadata">

**Author:** [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Replies:** 4\
**Last updated:** [August 15, 2025, 4:40pm UTC](https://discuss.elastic.co/t/esql-beginner-grouping-question/381054 "2025-08-15T16:40:11Z")

</div>

Hey, I am currently trying to convert a lengthy query DSL query with terms, top hits and max aggregations into a ESQL query, but I am failing at a basic requirement. Imagine the following three documents: PUT alr-test/…

---

## [ES|QL query to match a CIDR in a lookup index](https://discuss.elastic.co/t/es-ql-query-to-match-a-cidr-in-a-lookup-index/380849)

<div class="topic-metadata">

**Author:** [@rossw](https://discuss.elastic.co/u/rossw)\
**Replies:** 3\
**Last updated:** [August 7, 2025, 5:02am UTC](https://discuss.elastic.co/t/es-ql-query-to-match-a-cidr-in-a-lookup-index/380849 "2025-08-07T05:02:15Z")

</div>

Hi there. I am trying to create an ES|QL query that will match firewall records with a source.ip field against subnets listed as CIDR in a lookup table. Basically I’m trying to find events that originate from certain C…

---

## [ES|QL Query Controls](https://discuss.elastic.co/t/es-ql-query-controls/380444)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [July 28, 2025, 4:24pm UTC](https://discuss.elastic.co/t/es-ql-query-controls/380444 "2025-07-28T16:24:49Z")

</div>

Hello, Currently you can build a control through a ES|QL visualization The above is showing when you do the dynamic, building the control based off es|ql query. Is there plans to be able to create a control just ba…

---

## [How to use ES|QL control value as a filter](https://discuss.elastic.co/t/how-to-use-es-ql-control-value-as-a-filter/379716)

<div class="topic-metadata">

**Author:** [@tallakh](https://discuss.elastic.co/u/tallakh)\
**Replies:** 4\
**Last updated:** [July 9, 2025, 4:20am UTC](https://discuss.elastic.co/t/how-to-use-es-ql-control-value-as-a-filter/379716 "2025-07-09T04:20:27Z")

</div>

Hi! I'm testing out ES|QL controls in a dashboard, but I'm not able to use it as I expected. I've created a control with static values, but using the variable name in the query fails. According to this documentati…

---

## [Dashboard ES|QL Visualization configuration resets with every query change](https://discuss.elastic.co/t/dashboard-es-ql-visualization-configuration-resets-with-every-query-change/379813)

<div class="topic-metadata">

**Author:** [@allatrue](https://discuss.elastic.co/u/allatrue)\
**Replies:** 2\
**Last updated:** [July 5, 2025, 6:19pm UTC](https://discuss.elastic.co/t/dashboard-es-ql-visualization-configuration-resets-with-every-query-change/379813 "2025-07-05T18:19:11Z")

</div>

Hello everyone, I'm wondering if this is a normal behavior. When I make any change at ES|QL visualization query in a dashboard and click "Run query", the editor resets the visualization configuration, so that I have to …

---

## [Elastic search v8.18.2 fails to boot up in FIPS mode because of MD5 invocation in ESQL plugin](https://discuss.elastic.co/t/elastic-search-v8-18-2-fails-to-boot-up-in-fips-mode-because-of-md5-invocation-in-esql-plugin/379118)

<div class="topic-metadata">

**Author:** [@k.rajendran](https://discuss.elastic.co/u/k.rajendran)\
**Replies:** 3\
**Last updated:** [June 24, 2025, 2:42am UTC](https://discuss.elastic.co/t/elastic-search-v8-18-2-fails-to-boot-up-in-fips-mode-because-of-md5-invocation-in-esql-plugin/379118 "2025-06-24T02:42:22Z")

</div>

I am trying to upgrade our Elasticsearch FIPS enabled cluster from v8.17.4 to 8.18.2. When I tried doing this the initialization failed with this error: \[2025-06-09T20:46:40,119\]\[ERROR\]\[o.e.b.Elasticsearch \]\[elasticsear…

---

## [Field Exists like capability in ES|QL](https://discuss.elastic.co/t/field-exists-like-capability-in-es-ql/379089)

<div class="topic-metadata">

**Author:** [@ashit\_pupu](https://discuss.elastic.co/u/ashit_pupu)\
**Replies:** 2\
**Last updated:** [June 12, 2025, 5:32am UTC](https://discuss.elastic.co/t/field-exists-like-capability-in-es-ql/379089 "2025-06-12T05:32:27Z")

</div>

Hi Team Reaching out to understand if there is any functionality available in ES|QL which could handle if a field doesn't exist. Currently if a field has never been indexed we don't have the field name in index mapping …

---

## [Fetch top k frequent fields](https://discuss.elastic.co/t/fetch-top-k-frequent-fields/378928)

<div class="topic-metadata">

**Author:** [@Parthpuri\_Goswami](https://discuss.elastic.co/u/Parthpuri_Goswami)\
**Replies:** 3\
**Last updated:** [June 6, 2025, 7:53am UTC](https://discuss.elastic.co/t/fetch-top-k-frequent-fields/378928 "2025-06-06T07:53:57Z")

</div>

Hi all, I want to fetch the top k fields that are most frequent in the last 5 minutes of documents or in whole index. I have tried some queries, as shown below, to get the desired output, but it's taking a long time. I …

---

## [Filtering ESQL Panel in a Kibana Dashboard](https://discuss.elastic.co/t/filtering-esql-panel-in-a-kibana-dashboard/377805)

<div class="topic-metadata">

**Author:** [@etp](https://discuss.elastic.co/u/etp)\
**Replies:** 1\
**Last updated:** [May 5, 2025, 10:32am UTC](https://discuss.elastic.co/t/filtering-esql-panel-in-a-kibana-dashboard/377805 "2025-05-05T10:32:00Z")

</div>

I'm creating a dashboard which uses the usual KQL for most metric panels. I have a esql based Table also in the dashboard. When filtering on the dashboard level, I see that the esql based Table is empty. Is there any spe…

[Next page](https://discuss.elastic.co/tag/esql/149.md?match_all_tags=true&page=1&tags%5B%5D=esql)
