@jackd I presume you are referring to the traffic log query engine on the farewell/Panorama and yes, it is not very advanced and distinct or uniq function are definitely missing. We use external SIME solution with advanced queries capabilities, but for a small tasks I would export the logs and use Unix or some script to query them. You can also use the firewall local reporting engine to generate something similar. For example you can create a report on only unique source IPs hit count over a period of time, but this also has its limitation.
... View more