# Average value change when filtering or changing size

**URL:** <https://discuss.elastic.co/t/average-value-change-when-filtering-or-changing-size/107587>\
**Category:** Kibana\
**Created:** [November 14, 2017, 4:34pm UTC](https://discuss.elastic.co/t/average-value-change-when-filtering-or-changing-size/107587 "2017-11-14T16:34:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![LuigiAG](https://avatars.discourse-cdn.com/v4/letter/l/e9c0ed/32.png) [@LuigiAG](https://discuss.elastic.co/u/LuigiAG)\
**Post date:** [November 14, 2017, 4:34pm UTC](https://discuss.elastic.co/t/average-value-change-when-filtering-or-changing-size/107587/1 "2017-11-14T16:34:49Z")

</div>

Hi,

I had a weird issue when I was editing new visualization on kibana.  
I had the same issue with vertical bar and data table.

Here are the config :

![image](https://us1.discourse-cdn.com/elastic/original/3X/5/1/51439527142d226f4ce80848ee8752e2f4af8d34.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/0/5018a0916d40b6ac970e5c236c5ef05124d3cb29.png)

When the size of X axis is 129, I have this result :

![image](https://us1.discourse-cdn.com/elastic/original/3X/e/f/ef32bb25e999c377ec20f31a9746d3652d3f0c4d.png)

But when the size is 130 or when I only show the first value I have this :

![image](https://us1.discourse-cdn.com/elastic/original/3X/f/2/f25f3501f13f9f4ad53dbf8fd8f5da2c66418b07.png)

CH has loosing 34 000 in execution time.

The first value when I show 129 person is wrong.

One more thing the time range does not influence anything, all data are from 5 days ago and I look for the last 30 days.

If someone has a clue or need more info 🙂

Thanks

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [November 14, 2017, 8:42pm UTC](https://discuss.elastic.co/t/average-value-change-when-filtering-or-changing-size/107587/2 "2017-11-14T20:42:01Z")

</div>

This sounds like the effect of merging the results from independent shards into a single response, which is generally considered an approximation and with smaller result sizes (when compared to the cardinality) can sometimes result in inaccurate results. Check out [https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#\_shard\_size\_3](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#_shard_size_3)

I suggest using the `shard_size` parameter in your terms aggregation to ensure that it pulls back enough terms to get an accurate enough result for your use case. The correct number is really based on the cardinality of your field, and the way it is sharded, but it seems you have found a good number to start with.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 12, 2017, 8:42pm UTC](https://discuss.elastic.co/t/average-value-change-when-filtering-or-changing-size/107587/3 "2017-12-12T20:42:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
