> For the complete documentation index, see [llms.txt](https://sandyzeng.gitbook.io/kql/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://sandyzeng.gitbook.io/kql/kql-quick-guide/my-favorites/distinct.md).

# distinct

I often use distinct to look for the value that I want to use later as filters or parameters in workbooks. For example, I see IntuneDevices table has a column called ManageBy, but I have no ideas what data we have in this column.&#x20;

```
IntuneDevices
| where Result == 'None'
| where TimeGenerated > ago (30d)
| distinct OS, JoinType,Ownership, ManagedBy, DeviceRegistrationState
```

![](https://3533425259-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fbx8yn20QqNJtsVaH9CY7%2Fuploads%2F7hwxdC6kfEF5WJUlR69B%2Fimage.png?alt=media\&token=1deec9ec-6d2a-43eb-93fe-e602bcfa385b)

Now that I know that I have "Intune" and "Co-managed" values in ManagedBy, if I want to know what devices are Co-managed, I can run the following query

```
IntuneDevices
| where TimeGenerated > ago (7d) 
    and todatetime(LastContact) > ago(60d) //We need to convert LastContact to date time format
    and ManagedBy == 'Co-managed' //filter device are Co-managed
| summarize arg_max(TimeGenerated, *) by SerialNumber
```
