# API Search gives me a wrong bucket count

**URL:** <https://discuss.elastic.co/t/api-search-gives-me-a-wrong-bucket-count/60673>\
**Category:** Elasticsearch\
**Created:** [September 16, 2016, 6:39am UTC](https://discuss.elastic.co/t/api-search-gives-me-a-wrong-bucket-count/60673 "2016-09-16T06:39:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![xoxys](https://avatars.discourse-cdn.com/v4/letter/x/9dc877/32.png) [@xoxys](https://discuss.elastic.co/u/xoxys)\
**Post date:** [September 16, 2016, 6:39am UTC](https://discuss.elastic.co/t/api-search-gives-me-a-wrong-bucket-count/60673/1 "2016-09-16T06:39:05Z")

</div>

```
    *Elasticsearch version1.4.4*:

```

_OS versionRHEL7.2_:

Description of the problem including expected versus actual behavior:

Hi,

i use elasticsearch to collect logmessages. I try to get a overview of  
all hosts and the sum of logfiles in the last hour. To get the result i  
use the python client from elasticsearch and these query:

{

```
"aggs": {

    "hosts" : {

        "filter" : {

            "range" : {

                "@timestamp" : { "gt" : "now-1h" }

            }

        },

        "aggs" : {

            "logs_per_host" : {

                "terms" : {

                    "field" : "logsource",

                    "size" : 5000

                }

            }

        }

    }

}, "size" : 0

```

})

The field "logsource" contains the unique hostname of each server.  
The query runs well and i got buckets with the doc\_count of each host.  
The problem is the count of some hosts seems to be wrong. The query  
counts ~ 8000 logs in the last hour. If i verify the value of these  
hosts with kibana the count for this host is ~4500 logs. I also verify  
the count of this host with this es query:

{

```
    "aggs" : {

        "host" : { "filter" : { "term" : { "logsource" : hostname } },

            "aggs" : {

                 "logs_per_hour" : {

                    "date_histogram" : {

                        "field" : "@timestamp",

                        "interval" : "1h",

                        "order" : { "_count" : "asc" }

                    }

                }

            }

        }

```

}

This shows me that the host has ~ 4000 Logs per our, so the first query  
seems to be wrong. I dont know if this is a bug or the query is wrong...  
Some counts from the first query seems to be okay because the values  
matches with kibana and the secound query.

clintongormley told me on github:  
Hi @xoxys

You're using a top-level filter in the first query which is applied AFTER aggs are calculated.

But i dont know what this means. Can someone explain this a little bit more?  
Thanks

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [September 16, 2016, 3:01pm UTC](https://discuss.elastic.co/t/api-search-gives-me-a-wrong-bucket-count/60673/2 "2016-09-16T15:01:53Z")

</div>

You can read more about the post\_filter her:

- [https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-post-filter.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-post-filter.html)
- [https://www.elastic.co/guide/en/elasticsearch/guide/current/\_post\_filter.html](https://www.elastic.co/guide/en/elasticsearch/guide/current/_post_filter.html)

Basically, an aggregation gets the set of documents to aggregate from the `"query"` clause. So any documents matching the query will be aggregated. The filtering done by a `post_filter` happens _after_ the query, meaning the aggregation results are not affected by the post\_filter

To your first question: Terms aggregations can be approximate, depending on the sizes set. You can read more about it here: [https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#search-aggregations-bucket-terms-aggregation-approximate-counts](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#search-aggregations-bucket-terms-aggregation-approximate-counts)

It's not clear to me if this is your problem, perhaps you could show some of the results that look wrong?

---

<div class="post-metadata">

**Author:** ![xoxys](https://avatars.discourse-cdn.com/v4/letter/x/9dc877/32.png) [@xoxys](https://discuss.elastic.co/u/xoxys)\
**Post date:** [September 19, 2016, 6:53am UTC](https://discuss.elastic.co/t/api-search-gives-me-a-wrong-bucket-count/60673/3 "2016-09-19T06:53:02Z")

</div>

Sorry for the bad explanation. What i try to get is an overview of all Hosts and the count of logfiles for the last hour per host.

Buckets actually looks like this:  
Got 1076571 Hits  
{ u'buckets': [ { u'doc\_count': 8637, u'key': u'hosname1'},  
{ u'doc\_count': 4024, u'key': u'hostname2'},

Looks fine, the problem is that the count for hostname1 is not correct. Kibana tells me for this host at the last hour 3800. But the count for hostname2 is the same in elasticseacrh and Kibana. So it seems there is no problem in general but some hosts does not match...

If i try this query:  
"aggs" : {  
"host" : { "filter" : { "term" : { "logsource" : "hostname1" } },  
"aggs" : {  
"logs\_per\_hour" : {  
"date\_histogram" : {  
"field" : "@timestamp",  
"interval" : "1h",  
"order" : { "\_count" : "asc" }  
}  
}  
}  
}  
i got the same count as Kibana (3800) so i think this count is the right one. The question is why i got ~ 8700 with the first query? And why some hosts matches with kibana and some hosts not?  
Thank you again

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:19pm UTC](https://discuss.elastic.co/t/api-search-gives-me-a-wrong-bucket-count/60673/4 "2017-07-05T22:19:23Z")

</div>


