﻿---
title: Work with ES|QL results in Discover
description: Filter and sort ES|QL results in Discover, select columns, and turn on the time filter for a time field other than @timestamp.
url: https://www.elastic.co/elastic/docs-builder/docs/4302/explore-analyze/discover/esql-results
products:
  - Elastic Documentation
  - Kibana
applies_to:
  - Elastic Cloud Serverless: Generally available
  - Elastic Stack: Generally available
---

# Work with ES|QL results in Discover
After an ES|QL query runs in **Discover**, the results table shows what that query returned. You can filter the rows, sort them, and show the fields you want. You can also set the time filter, and the table and the chart use that time range.
- **Rows:** [Filter from a value](#refine-esql-query-from-table), or [sort rows or change which rows the query returns](#_sorting). [Show more than 1,000 rows](#esql-kibana-results-table-limitations) with `LIMIT`.
- **Columns:** [Show the fields you want](#esql-kibana-results-table), from the fields list or with `KEEP`. The table displays at most 50 columns.
- **Time filter and chart:** [Set the time filter for the table and the chart](#_esql_and_time_series_data). Discover applies the time filter when the data has an `@timestamp` field. If the time field has another name, name it in the query.

To keep the chart or the table, [save the session or add it to a dashboard](#_edit_the_esql_visualization).

## Before you begin

- You need an ES|QL query in **Discover** that returns rows. If you're new to ES|QL in Discover, start with [Get started with ES|QL in Discover](https://www.elastic.co/elastic/docs-builder/docs/4302/explore-analyze/discover/try-esql).


## Filter from a value in the results table

Hover over a value in the results table, then filter for it or filter it out.
- `plus_circle` **Filter for this** keeps that value. For example, `WHERE `machine.os` == "osx"`.
- `minus_circle` **Filter out this** excludes that value. For example, `WHERE `machine.os` != "osx"`.
  ![The value osx in the machine.os column, with Filter out this available.](https://www.elastic.co/elastic/docs-builder/docs/4302/explore-analyze/images/kibana-discover-esql-filter-out.png)

<note applies-to="Elastic Cloud Serverless: Generally available, Elastic Stack: Generally available since 9.3">
  Filtering for multi-value fields translates into `WHERE MV_CONTAINS` or `WHERE NOT MV_CONTAINS` clauses. For example, `WHERE MV_CONTAINS(`tags.keyword`, ["error", "security"]::keyword)`.
</note>

ES|QL mode has no filter bar, and dragging a field onto the table doesn't change the query.
**Result:** When you select **Filter for this** or **Filter out this**, Discover adds or completes a `WHERE` clause for that value, and the table shows the matching rows.
![An ES|QL query with a WHERE clause that excludes osx from machine.os.](https://www.elastic.co/elastic/docs-builder/docs/4302/explore-analyze/images/kibana-discover-esql-filter-where.png)


## Sort query results

From the menu of a column, select **Sort High-Low** or **Sort Low-High**. Discover reorders the rows already in the table. The query stays the same, and Discover doesn't run it again.
![The menu for the bytes column, with Sort High-Low highlighted.](https://www.elastic.co/elastic/docs-builder/docs/4302/explore-analyze/images/kibana-discover-esql-sort-column.png)

**Result:** The table shows those same rows in the new order, and the query has no `SORT` command.
![The ES|QL query after a column sort. The query has no SORT command.](https://www.elastic.co/elastic/docs-builder/docs/4302/explore-analyze/images/kibana-discover-esql-sort-query.png)

<tip>
  A column sort reorders only the rows the query returned. For a `FROM` query with no `LIMIT`, that is at most 1,000 rows. To change which rows come back, add a [`SORT`](https://docs-v3-preview.elastic.dev/elastic/docs-builder/docs/4302/reference/query-languages/esql/commands/sort) command. Elasticsearch orders the data, then keeps the first rows of that order. This query returns the 1,000 largest `bytes` values:
  ```esql
  FROM kibana_sample_data_logs
  | KEEP @timestamp, bytes, geo.dest
  | SORT bytes DESC
  ```
</tip>


## Show specific columns in the results table


### The Summary column and the time field

Until you add fields, the table shows a **Summary** column of each result's key-value pairs. The time field is the first column when the data has `@timestamp`, or when the query names that field.
<note applies-to="Elastic Cloud Serverless: Generally available, Elastic Stack: Generally available since 9.4">
  When a query without a command such as `KEEP` or `STATS` returns five or fewer columns, **Discover** shows each column individually instead of the **Summary** column.
</note>

To hide the time field, enable [**Hide 'Time' column** (`doc_table:hideTimeColumn`)](https://docs-v3-preview.elastic.dev/elastic/docs-builder/docs/4302/reference/kibana/advanced-settings#kibana-discover-settings).

### Add a column from the fields list

Add a field from the [fields list](/elastic/docs-builder/docs/4302/explore-analyze/discover/discover-get-started#explore-fields-in-your-data) to show it as its own column. The query stays the same.
<applies-to>Elastic Cloud Serverless: Generally available</applies-to> <applies-to>Elastic Stack: Generally available since 9.5</applies-to> When the query has no command such as `KEEP` or `STATS`, the time field stays the first column after you add other fields. CSV exports from **Discover** and from Discover session panels on dashboards also include the time field.

### Return specific fields with `KEEP`

To control which fields the query returns, use the [`KEEP`](https://docs-v3-preview.elastic.dev/elastic/docs-builder/docs/4302/reference/query-languages/esql/commands/keep) command:
```esql
FROM kibana_sample_data_logs
| KEEP bytes, geo.dest, machine.os, response.keyword
```

![A KEEP query that omits @timestamp. The time filter is set, and the chart and table use that range.](https://www.elastic.co/elastic/docs-builder/docs/4302/explore-analyze/images/kibana-discover-esql-keep-time-filter.png)

To display all fields as separate columns, use `KEEP *`:
```esql
FROM kibana_sample_data_logs
| KEEP *
```


## Row and column limits

If you omit `LIMIT`, the table shows up to 1,000 rows, or up to 10,000 rows for queries that start with `TS` or `PROMQL`. `LIMIT` can raise that to 10,000, which is as many rows as Discover displays. Aggregations still run on the full data set.
- **Column limit:** Discover displays up to 50 columns. If a query returns more than 50 columns, only the first 50 are shown.
- **CSV export:** CSV exports from Discover are also limited to 10,000 rows. Queries and aggregations still run on the full data set.


## Set the time filter for the table and the chart

When the data has an `@timestamp` field, the time filter applies to the table and the chart.
If the time field has another name, name it in the query with the `?_tstart` and `?_tend` parameters. For the editor behavior, refer to [Custom time parameters](/elastic/docs-builder/docs/4302/explore-analyze/query-filter/languages/esql-kibana#_custom_time_parameters).
For example, the eCommerce sample data set has no `@timestamp` field. It has an `order_date` field. With this query, the time filter doesn't apply, and Discover shows no chart:
```esql
FROM kibana_sample_data_ecommerce
```

Add the parameters on `order_date`. The time filter then applies, and Discover shows the chart.
```esql
FROM kibana_sample_data_ecommerce
| WHERE order_date >= ?_tstart AND order_date <= ?_tend
| LIMIT 100
```

![The eCommerce sample with order_date named as the time field. The time filter and the chart are available.](https://www.elastic.co/elastic/docs-builder/docs/4302/explore-analyze/images/kibana-discover-esql-order-date.png)

**Result:** The time filter sets the time range for that table and chart.

## Keep the chart or the table

To keep the chart or the table, use one of these options:
- **Save the Discover session.** [Save a Discover session for reuse](https://www.elastic.co/elastic/docs-builder/docs/4302/explore-analyze/discover/save-open-search) explains the options.
- <applies-to>Elastic Cloud Serverless: Generally available</applies-to> <applies-to>Elastic Stack: Generally available since 9.4</applies-to> **Save the table to a dashboard.** [Customize the table](/elastic/docs-builder/docs/4302/explore-analyze/discover/document-explorer#document-explorer-customize) explains how to configure it before you [save it](/elastic/docs-builder/docs/4302/explore-analyze/discover/save-open-search#save-table-to-dashboard).
- **Save the chart to a dashboard.** [Change the chart type and display options](/elastic/docs-builder/docs/4302/explore-analyze/visualize/esorql#_edit_and_add_from_discover) explains how to configure it before you [save it](/elastic/docs-builder/docs/4302/explore-analyze/discover/save-open-search#add-discover-visualization-esql).


## Related pages

- [Use Discover with ES|QL](https://www.elastic.co/elastic/docs-builder/docs/4302/explore-analyze/discover/use-esql)
- [Analyze your data with AI](/elastic/docs-builder/docs/4302/explore-analyze/discover/discover-get-started#analyze-with-ai)
- [Inspect grouped STATS results in Discover](https://www.elastic.co/elastic/docs-builder/docs/4302/explore-analyze/discover/inspect-grouped-stats)
- [Save a Discover session for reuse](https://www.elastic.co/elastic/docs-builder/docs/4302/explore-analyze/discover/save-open-search)
- [Customize the Discover view](https://www.elastic.co/elastic/docs-builder/docs/4302/explore-analyze/discover/document-explorer)