# Cardinality and value\_count aggr values are 200-500% off

**URL:** <https://discuss.elastic.co/t/cardinality-and-value-count-aggr-values-are-200-500-off/75803>\
**Category:** Elasticsearch\
**Created:** [February 21, 2017, 1:00am UTC](https://discuss.elastic.co/t/cardinality-and-value-count-aggr-values-are-200-500-off/75803 "2017-02-21T01:00:41Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![kievbs](https://avatars.discourse-cdn.com/v4/letter/k/e19adc/32.png) [@kievbs](https://discuss.elastic.co/u/kievbs)\
**Post date:** [February 21, 2017, 1:00am UTC](https://discuss.elastic.co/t/cardinality-and-value-count-aggr-values-are-200-500-off/75803/1 "2017-02-21T01:00:41Z")

</div>

I have the really weird issue with ES 2.4. Really appreciate if someone would explain me how to fix it.

I have an index with one unique field 'some\_id' inside - and the value of that field is used as object ID.

Total count of records is 756,451 - and all field values are unique (since used in doc ID).

Now I am running cardinality and value\_count aggr (see request below).  
value\_count gives me 3,782,132 -- it's 5x more than the total count!!  
cardinality - 1,598,725 -- 2x more than total count

We store UUID in this some\_id field, so values look like '06e58e84-e8ad-4d5f-be00-17f2b18ff668' etc (all unique).

Any idea why it happens? I realize that cardinality and value\_count are approx counts - but I didn't expect it has 200-500% error rate!!!

Thank you,

{  
"query": {  
"filtered": {  
"query": {  
"match\_all": []  
}  
}  
},  
"aggs": {  
"unique\_dev\_count": {  
"cardinality": {  
"field": "some\_id"  
}  
},  
"dev\_count": {  
"value\_count": {  
"field": "some\_id"  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![colings86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/colings86/32/44960_2.png) [@colings86](https://discuss.elastic.co/u/colings86)\
**Post date:** [February 21, 2017, 9:25am UTC](https://discuss.elastic.co/t/cardinality-and-value-count-aggr-values-are-200-500-off/75803/2 "2017-02-21T09:25:27Z")

</div>

You are right that the cardinality aggregation is approximate but the value\_count aggregation is not approximate. What is the mapping for your `some_id` field? My initial thought is that the field is an analyzed string field. This would mean that your UUID is being split up into multiple tokens on the `-` characters and this is causing the over counting your are seeing (because each document then has 5 values since your UUDI has 5 parts). If you change your `some_id` field to be `"index": "not_analyzed"` I think you'll see the results you expect.

Hope that helps

---

<div class="post-metadata">

**Author:** ![kievbs](https://avatars.discourse-cdn.com/v4/letter/k/e19adc/32.png) [@kievbs](https://discuss.elastic.co/u/kievbs)\
**Post date:** [February 21, 2017, 4:42pm UTC](https://discuss.elastic.co/t/cardinality-and-value-count-aggr-values-are-200-500-off/75803/3 "2017-02-21T16:42:34Z")

</div>

Thanks for your response. You're right - it had wrong mapping! I checked mapping first thing but looks like I didn't use correct env config. After fixing mapping and reindexing all good!

---

<div class="post-metadata">

**Author:** ![colings86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/colings86/32/44960_2.png) [@colings86](https://discuss.elastic.co/u/colings86)\
**Post date:** [February 21, 2017, 4:57pm UTC](https://discuss.elastic.co/t/cardinality-and-value-count-aggr-values-are-200-500-off/75803/4 "2017-02-21T16:57:13Z")

</div>

Glad to hear you fixed it 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 21, 2017, 4:57pm UTC](https://discuss.elastic.co/t/cardinality-and-value-count-aggr-values-are-200-500-off/75803/5 "2017-03-21T16:57:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
