# Aggregation query

**URL:** <https://discuss.elastic.co/t/aggregation-query/19304>\
**Category:** Elasticsearch\
**Created:** [August 15, 2014, 3:46pm UTC](https://discuss.elastic.co/t/aggregation-query/19304 "2014-08-15T15:46:33Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ivan\_Stone](https://avatars.discourse-cdn.com/v4/letter/i/bc79bd/32.png) [@Ivan\_Stone](https://discuss.elastic.co/u/Ivan_Stone)\
**Post date:** [August 15, 2014, 3:46pm UTC](https://discuss.elastic.co/t/aggregation-query/19304/1 "2014-08-15T15:46:33Z")

</div>

When I run the following query on a 5 shard ES db I don't get accurate  
results. I have had to reduce the amount of shards on my ES server to 1 to  
get the accuracy I need? Has anyone had a similar issue?

GET /incidents/\_search?search\_type=count  
{  
"query" : {  
"filtered" : {  
"filter" : {  
"bool" : {  
"must": {  
"range" : {  
"Date" : {  
"from" : "2014-08-05T00:00:00.000Z",  
"to" : "2014-08-06T00:00:00.000Z"  
}  
}  
},  
"must": {  
"exists" : { "field" : "AttackTypes" }  
}  
}  
}  
}  
},  
"aggs": {  
"by\_attackType" : {  
"terms": {  
"field": "AttackTypes",  
"order": {  
"\_count": "desc"  
},  
"shard\_size": 0,  
"size": 10  
},  
"aggs": {  
"by\_perpertrator" : {  
"terms": {  
"field": "Perpetrators",  
"order": {  
"\_term": "asc"  
},  
"min\_doc\_count": 0,  
"shard\_size": 0,  
"size": 0  
}  
}  
}  
}  
}  
}

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/cf1f5980-717d-4da9-b55b-3262a284e144%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/cf1f5980-717d-4da9-b55b-3262a284e144%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![vineeth\_mohan\_2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vineeth_mohan_2/32/747_2.png) [@vineeth\_mohan\_2](https://discuss.elastic.co/u/vineeth_mohan_2)\
**Post date:** [August 16, 2014, 4:54am UTC](https://discuss.elastic.co/t/aggregation-query/19304/2 "2014-08-16T04:54:13Z")

</div>

Hello Ivan ,

This is expected.  
Only the top N(size mentioned in aggregation) results are taken from each  
shard before reducing the result.  
Due this , the accuracy is not guaranteed but the order is guaranteed.  
As a fix , you can use this to improve accuracy at the cost of memory -

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

Thanks  
Vineeth

On Fri, Aug 15, 2014 at 9:16 PM, Ivan Stone [reachout2me@gmail.com](mailto:reachout2me@gmail.com) wrote:

> When I run the following query on a 5 shard ES db I don't get accurate  
> results. I have had to reduce the amount of shards on my ES server to 1 to  
> get the accuracy I need? Has anyone had a similar issue?
> 
> GET /incidents/\_search?search\_type=count  
> {  
> "query" : {  
> "filtered" : {  
> "filter" : {  
> "bool" : {  
> "must": {  
> "range" : {  
> "Date" : {  
> "from" : "2014-08-05T00:00:00.000Z",  
> "to" : "2014-08-06T00:00:00.000Z"  
> }  
> }  
> },  
> "must": {  
> "exists" : { "field" : "AttackTypes" }  
> }  
> }  
> }  
> }  
> },  
> "aggs": {  
> "by\_attackType" : {  
> "terms": {  
> "field": "AttackTypes",  
> "order": {  
> "\_count": "desc"  
> },  
> "shard\_size": 0,  
> "size": 10  
> },  
> "aggs": {  
> "by\_perpertrator" : {  
> "terms": {  
> "field": "Perpetrators",  
> "order": {  
> "\_term": "asc"  
> },  
> "min\_doc\_count": 0,  
> "shard\_size": 0,  
> "size": 0  
> }  
> }  
> }  
> }  
> }  
> }
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/cf1f5980-717d-4da9-b55b-3262a284e144%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/cf1f5980-717d-4da9-b55b-3262a284e144%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/cf1f5980-717d-4da9-b55b-3262a284e144%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/cf1f5980-717d-4da9-b55b-3262a284e144%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAGdPd5m%3DTcrAtwCO7ovfjRgnO%2BbmxP8DEK%2BRmUvEsyE-1taYcQ%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAGdPd5m%3DTcrAtwCO7ovfjRgnO%2BbmxP8DEK%2BRmUvEsyE-1taYcQ%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:08am UTC](https://discuss.elastic.co/t/aggregation-query/19304/3 "2017-07-06T01:08:10Z")

</div>


