# Different Results Based on Aggregation Size

**URL:** <https://discuss.elastic.co/t/different-results-based-on-aggregation-size/56202>\
**Category:** Kibana\
**Created:** [July 22, 2016, 6:23pm UTC](https://discuss.elastic.co/t/different-results-based-on-aggregation-size/56202 "2016-07-22T18:23:19Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shane\_Daniel](https://avatars.discourse-cdn.com/v4/letter/s/7ba0ec/32.png) [@Shane\_Daniel](https://discuss.elastic.co/u/Shane_Daniel)\
**Post date:** [July 22, 2016, 6:23pm UTC](https://discuss.elastic.co/t/different-results-based-on-aggregation-size/56202/1 "2016-07-22T18:23:19Z")

</div>

I'm getting different results depending on selected _Size_.

Steps to reproduce in Kibana:

1. Create vertical bar chart
2. metrics \> Y-Axis \> Aggregation: Average
3. metrics \> Y-Axis \> Field: select a numerical field
4. buckets \> X-Axis \> Aggregation: Terms
5. buckets \> X-Axis \> Field: select a string field
6. buckets \> X-Axis \> Order by: select metric: Average
7. buckets \> X-Axis \> Order: Descending
8. buckets \> X-Axis \> Size: 10

For my data the first bar has a value of 1,918.84. It is using a document count of 5 to calculate this result.

If I change _buckets \> X-Axis \> Size_: 30, the first bar has a value of 1,373.61. It is using a document count of 7 to calculate this result.

If I change _buckets \> X-Axis \> Size_: 0, the first bar has a value of 962.51. It is using a document count of 10 to calculate this result. I believe this to be the correct value.

There are 10 documents with the value associated with the first bar, and a total count of 13,902 in total document Hits.

I'm concerned as the returned values are quite inaccurate, and I cannot set Size: 0 as there are too many bars. Is there a recommended solution?

---

<div class="post-metadata">

**Author:** ![BigFunger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigfunger/32/7323_2.png) [@BigFunger](https://discuss.elastic.co/u/BigFunger)\
**Post date:** [July 22, 2016, 7:30pm UTC](https://discuss.elastic.co/t/different-results-based-on-aggregation-size/56202/2 "2016-07-22T19:30:17Z")

</div>

Can you provide me with a sample of your data with which I can reproduce this problem?

---

<div class="post-metadata">

**Author:** ![Shane\_Daniel](https://avatars.discourse-cdn.com/v4/letter/s/7ba0ec/32.png) [@Shane\_Daniel](https://discuss.elastic.co/u/Shane_Daniel)\
**Post date:** [July 22, 2016, 8:02pm UTC](https://discuss.elastic.co/t/different-results-based-on-aggregation-size/56202/3 "2016-07-22T20:02:23Z")

</div>

Thanks for the response Jim. Unfortunately I can't share the particular data set I'm working with.

I tried to create a similar scenario using [http://demo.elastic.co/packetbeat](http://demo.elastic.co/packetbeat)

Time filter: From: 2016-07-21 23:00:00.000 To: 2016-07-22 00:00:59.999

Create vertical bar chart (index: packetbeat-\*)

metrics \> Y-Axis \> Aggregation: Average  
metrics \> Y-Axis \> Field: responsetime  
metrics \> +Add metric  
metrics \> Y-Axis (2) \> Aggregation: Count

buckets \> X-Axis \> Aggregation: Terms  
buckets \> X-Axis \> Field: query  
buckets \> X-Axis \> Order: Top  
buckets \> X-Axis \> Size: 3  
buckets \> X-Axis \> Order By: metric: Average responsetime

Here the first bar, test.users.find() has a count of 8 and an avg responsetime of 91.125.  
Also the third bar, "GET /static/img/paper\_fibers.png HTTP/1.1" has a count of 1 and an avg responsetime of 59.

Changing,  
buckets \> X-Axis \> Size: 100

Now test.users.find() has a count of 9 and an avg responsetime of 84.667.  
Also, "GET /static/img/paper\_fibers.png HTTP/1.1" now has a count of 2 and an avg responsetime of 44.5

---

<div class="post-metadata">

**Author:** ![BigFunger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigfunger/32/7323_2.png) [@BigFunger](https://discuss.elastic.co/u/BigFunger)\
**Post date:** [July 26, 2016, 7:30pm UTC](https://discuss.elastic.co/t/different-results-based-on-aggregation-size/56202/4 "2016-07-26T19:30:47Z")

</div>

@Shane_Daniel,

I agree that the results that you mentioned do sound suspect, and would like to investigate it further, but need to be able to reproduce the issue.

I tried to recreate what you described above. I assume it's because the demo data changed since you set this up. (see image to make sure I didn't screw anything up)

 ![](https://us1.discourse-cdn.com/elastic/original/2X/f/fdd9f2a9fd23b7b5f409787048d34e43e5805b72.png)

---

<div class="post-metadata">

**Author:** ![Shane\_Daniel](https://avatars.discourse-cdn.com/v4/letter/s/7ba0ec/32.png) [@Shane\_Daniel](https://discuss.elastic.co/u/Shane_Daniel)\
**Post date:** [July 26, 2016, 8:46pm UTC](https://discuss.elastic.co/t/different-results-based-on-aggregation-size/56202/5 "2016-07-26T20:46:42Z")

</div>

@BigFunger,

Yes, it looks like the data I used in the example has been purged.

I was able to resolve my issue by setting X-Axis \> JSON Input \> {"shard\_size":0}

For other readers information the description of the shard\_size parameter can be found here:  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#\_shard\_size\_2](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#_shard_size_2)

---

<div class="post-metadata">

**Author:** ![BigFunger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigfunger/32/7323_2.png) [@BigFunger](https://discuss.elastic.co/u/BigFunger)\
**Post date:** [July 26, 2016, 8:49pm UTC](https://discuss.elastic.co/t/different-results-based-on-aggregation-size/56202/6 "2016-07-26T20:49:04Z")

</div>

@Shane_Daniel,

Thanks for posting your solution! Wish I could have been more help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:43pm UTC](https://discuss.elastic.co/t/different-results-based-on-aggregation-size/56202/7 "2017-07-06T13:43:39Z")

</div>


