# Aggregation returning contradictory results

**URL:** <https://discuss.elastic.co/t/aggregation-returning-contradictory-results/249058>\
**Category:** Elasticsearch\
**Created:** [September 18, 2020, 5:31am UTC](https://discuss.elastic.co/t/aggregation-returning-contradictory-results/249058 "2020-09-18T05:31:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Xavier\_Marti\_Bofill](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xavier_marti_bofill/32/67923_2.png) [@Xavier\_Marti\_Bofill](https://discuss.elastic.co/u/Xavier_Marti_Bofill)\
**Post date:** [September 18, 2020, 5:31am UTC](https://discuss.elastic.co/t/aggregation-returning-contradictory-results/249058/1 "2020-09-18T05:31:58Z")

</div>

Our elasticsearch cluster is returning is contradictory results. We execute the following query, searching for values below 480 (that would mean we have a problem):

```auto
{
  "aggs": {
    "2": {
      "terms": {
        "field": "tenant",
        "order": {"_count": "desc"},
        "size": 20
      }
    }
  },
  "size": 0,
  "track_total_hits" : true,
  "query": {
    "bool": {
      "filter": [
        {"match_phrase": {"source": "JOB"}},
        {"match_phrase": {"profile": "producer"}},
        {"match_phrase": {"type": "SECTION"}},
        {"match_phrase": {"sectionIndex": "0"}},
        {
          "range": {
            "timestamp": {
              "gte": "2020-09-16T08:00:00.000Z",
              "lte": "2020-09-17T08:00:00.000Z",
              "format": "strict_date_optional_time"
            }
          }
        }
      ]
    }
  }
}

```

**Which returns:**

```auto
{
  "took" : 61,
  "timed_out" : false,
  "_shards" : {
    "total" : 36,
    "successful" : 36,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 324476,
      "relation" : "eq"
    },
    "max_score" : null,
    "hits" : []
  },
  "aggregations" : {
    "2" : {
      "doc_count_error_upper_bound" : 609,
      "sum_other_doc_count" : 308229,
      "buckets" : [
        {
          "key" : "domain1.net",
          "doc_count" : 1440
        },
        {
          "key" : "domain2.pe",
          "doc_count" : 1440
        },
        {
          "key" : "domain3.com",
          "doc_count" : 1440
        },
        {
          "key" : "www.domain4.net",
          "doc_count" : 1440
        },
        {
          "key" : "www.domain5.com",
          "doc_count" : 1440
        },
        {
          "key" : "www.domain6.es",
          "doc_count" : 1440
        },
        {
          "key" : "domain7.com",
          "doc_count" : 960
        },
        {
          "key" : "m.domain8.ba",
          "doc_count" : 960
        },
        {
          "key" : "domain9.com",
          "doc_count" : 960
        },
        {
          "key" : "www.domain10.cl",
          "doc_count" : 960
        },
        {
          "key" : "www.domain11.cl",
          "doc_count" : 960
        },
        {
          "key" : "www.domain12.com",
          "doc_count" : 960
        },
        {
          "key" : "www.domain13.net",
          "doc_count" : 959
        },
        {
          "key" : "www.domain14.com",
          "doc_count" : 158
        },
        {
          "key" : "domain15.fr",
          "doc_count" : 156
        },
        {
          "key" : "domain16.com",
          "doc_count" : 121
        },
        {
          "key" : "domain17.com",
          "doc_count" : 117
        },
        {
          "key" : "pre.domain18.com",
          "doc_count" : 116
        },
        {
          "key" : "domain19.com.br",
          "doc_count" : 110
        },
        {
          "key" : "m.domain20.com.py",
          "doc_count" : 110
        }
      ]
    }
  }
}

```

So, we go after one of these low results, and we add to the filter:

```auto
 {"match_phrase": {"tenant": "domain15.fr"}},

```

**And we get:**

```auto
{
  "took" : 12,
  "timed_out" : false,
  "_shards" : {
    "total" : 36,
    "successful" : 36,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 480,
      "relation" : "eq"
    },
    "max_score" : null,
    "hits" : []
  },
  "aggregations" : {
    "2" : {
      "doc_count_error_upper_bound" : 0,
      "sum_other_doc_count" : 0,
      "buckets" : [
        {
          "key" : "domain15.fr",
          "doc_count" : 480
        }
      ]
    }
  }
}

```

Contradicting itself. This happens with every domain we have tried, every time. It's reproducible and consistent.

Any idea?

---

<div class="post-metadata">

**Author:** ![thiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago/32/32096_2.png) [@thiago](https://discuss.elastic.co/u/thiago)\
**Post date:** [September 21, 2020, 4:22pm UTC](https://discuss.elastic.co/t/aggregation-returning-contradictory-results/249058/2 "2020-09-21T16:22:58Z")

</div>

Your first result has `doc_count_error_upper_bound` and `sum_other_doc_count` above zero, which means approximate results. See [terms aggregation document counts are approximate](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#search-aggregations-bucket-terms-aggregation-size) for more context.

Increasing the `size` parameter will help with accuracy, but can hurt performance. In this case try setting a [shard size](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#_shard_size_3) or maybe use the [composite aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-composite-aggregation.html).

Best

---

<div class="post-metadata">

**Author:** ![Xavier\_Marti\_Bofill](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xavier_marti_bofill/32/67923_2.png) [@Xavier\_Marti\_Bofill](https://discuss.elastic.co/u/Xavier_Marti_Bofill)\
**Post date:** [October 6, 2020, 9:43am UTC](https://discuss.elastic.co/t/aggregation-returning-contradictory-results/249058/3 "2020-10-06T09:43:43Z")

</div>

Clear, thanks! A bummer, though.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2020, 9:43am UTC](https://discuss.elastic.co/t/aggregation-returning-contradictory-results/249058/4 "2020-11-03T09:43:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
