# Both the queries seem same , but the count is different . WHY?

**URL:** <https://discuss.elastic.co/t/both-the-queries-seem-same-but-the-count-is-different-why/64550>\
**Category:** Kibana\
**Created:** [November 1, 2016, 12:00pm UTC](https://discuss.elastic.co/t/both-the-queries-seem-same-but-the-count-is-different-why/64550 "2016-11-01T12:00:12Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rupam\_Sarkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rupam_sarkar/32/12868_2.png) [@Rupam\_Sarkar](https://discuss.elastic.co/u/Rupam_Sarkar)\
**Post date:** [November 1, 2016, 12:00pm UTC](https://discuss.elastic.co/t/both-the-queries-seem-same-but-the-count-is-different-why/64550/1 "2016-11-01T12:00:12Z")

</div>

_ **1st query:** _

```
   {
  "size": 0,
  "aggs": {
    "2": {
      "terms": {
        "field": "appName",
        "size": 100,
        "order": {
          "1": "desc"
        }
      },
      "aggs": {
        "1": {
          "cardinality": {
            "field": "userId"
          }
        }
      }
    }
  },
  "query": {
    "filtered": {
      "query": {
        "query_string": {
          "query": "eventName :IncomingRequest",
          "analyze_wildcard": true
        }
      },
      "filter": {
        "bool": {
          "must": [
            {
              "query": {
                "match": {
                  "appName": {
                    "query": "opsprodai",
                    "type": "phrase"
                  }
                }
              },
              "$state": {
                "store": "appState"
              }
            },
            {
              "query": {
                "query_string": {
                  "analyze_wildcard": true,
                  "query": "*"
                }
              }
            },
            {
              "range": {
                "telemetryEventTime": {
                  "gte": 1475406373747,
                  "lte": 1477998373747,
                  "format": "epoch_millis"
                }
              }
            }
          ],
          "must_not": []
        }
      }
    }
  },
  "highlight": {
    "pre_tags": [
      "@kibana-highlighted-field@"
    ],
    "post_tags": [
      "@/kibana-highlighted-field@"
    ],
    "fields": {
      "*": {}
    },
    "require_field_match": false,
    "fragment_size": 2147483647
  }
}

```

**_2nd Query_**

```
{
  "size": 0,
  "aggs": {
    "1": {
      "cardinality": {
        "field": "userId"
      }
    }
  },
  "query": {
    "filtered": {
      "query": {
        "query_string": {
          "query": "eventName :IncomingRequest",
          "analyze_wildcard": true
        }
      },
      "filter": {
        "bool": {
          "must": [
            {
              "query": {
                "match": {
                  "appName": {
                    "query": "opsprodai",
                    "type": "phrase"
                  }
                }
              },
              "$state": {
                "store": "appState"
              }
            },
            {
              "query": {
                "query_string": {
                  "analyze_wildcard": true,
                  "query": "*"
                }
              }
            },
            {
              "range": {
                "telemetryEventTime": {
                  "gte": 1475406373747,
                  "lte": 1477998373747,
                  "format": "epoch_millis"
                }
              }
            }
          ],
          "must_not": []
        }
      }
    }
  },
  "highlight": {
    "pre_tags": [
      "@kibana-highlighted-field@"
    ],
    "post_tags": [
      "@/kibana-highlighted-field@"
    ],
    "fields": {
      "*": {}
    },
    "require_field_match": false,
    "fragment_size": 2147483647
  }
}

```

I want to count unique users for each application . but the outcome of these two queries for the app "opsprodai" are not equal .😞

---

<div class="post-metadata">

**Author:** ![tylersmalley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylersmalley/32/8833_2.png) [@tylersmalley](https://discuss.elastic.co/u/tylersmalley)\
**Post date:** [November 2, 2016, 6:02am UTC](https://discuss.elastic.co/t/both-the-queries-seem-same-but-the-count-is-different-why/64550/2 "2016-11-02T06:02:28Z")

</div>

How far off are the counts? A cardinality aggregation should be treated as an approximation.

More information on approximate counts: [https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-metrics-cardinality-aggregation.html#\_counts\_are\_approximate](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-metrics-cardinality-aggregation.html#_counts_are_approximate)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:34pm UTC](https://discuss.elastic.co/t/both-the-queries-seem-same-but-the-count-is-different-why/64550/3 "2017-07-06T13:34:52Z")

</div>


