# Discover Tab filters data incorrectly

**URL:** <https://discuss.elastic.co/t/discover-tab-filters-data-incorrectly/130040>\
**Category:** Kibana\
**Created:** [April 30, 2018, 3:08pm UTC](https://discuss.elastic.co/t/discover-tab-filters-data-incorrectly/130040 "2018-04-30T15:08:18Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![pavithrakc](https://avatars.discourse-cdn.com/v4/letter/p/a6a055/32.png) [@pavithrakc](https://discuss.elastic.co/u/pavithrakc)\
**Post date:** [April 30, 2018, 3:08pm UTC](https://discuss.elastic.co/t/discover-tab-filters-data-incorrectly/130040/1 "2018-04-30T15:08:18Z")

</div>

Hello all,

I am trying to filter data based on TRADENUMBER in my discover tab. It shows incorrect results. It retrieves data for other Tradenumber's too.

I did a query on elasticsearch too. I get same results which is actually wrong.

TRADENUMBER - number  
Version - [docker.elastic.co/kibana/kibana-oss:6.2.2](http://docker.elastic.co/kibana/kibana-oss:6.2.2)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/1/a135bfc18ba6331333b203ea2199ed5cee98b0d8.png)

I do have same setup in different version of elasticsearch and kibana instance running on docker.  
Version: [docker.elastic.co/kibana/kibana:5.6.2](http://docker.elastic.co/kibana/kibana:5.6.2)

In this one, if I do the same query I get perfect results (1 hit).

Please the see below screenshot for the same.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/3/53a5051cef8c86039ef168e5cf2b0895c378d4ee.png)

It looks very strange for me.

Other differences between these two instances are:

Recent version 6.2.2 use time-based indices and other one 5.6.2 use normal index.

Please advise.

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [April 30, 2018, 4:05pm UTC](https://discuss.elastic.co/t/discover-tab-filters-data-incorrectly/130040/2 "2018-04-30T16:05:15Z")

</div>

It looks like your filter is a string like "615,160,670", which would be analyzed and split by the commas into 3 terms. So your results are any TRADENUMBER which contains "615" or "160" or "670".

Is your TRADENUMBER a number type (when you look at the index pattern in the Management tab?

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [April 30, 2018, 5:42pm UTC](https://discuss.elastic.co/t/discover-tab-filters-data-incorrectly/130040/3 "2018-04-30T17:42:43Z")

</div>

I could be wrong there. When I add a filter by clicking on some percentage number value I get this, which appears to be searching for a string;

![image](https://us1.discourse-cdn.com/elastic/original/3X/e/b/ebe4c30ab72d3e0c5e7c7d4d2659c8eb139f9b54.png)

But if I edit the filter I get the decimal number;

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/b/fb424ea88fc8ef6157b35b73cf15dd013657b694.png)

And one step further to `Edit Query DSL` I see this;

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/5/35c99b968c4e034b57224e0f36a84474db82e580.png)

Can you check your filter and see if it's really doing the numeric query?

---

<div class="post-metadata">

**Author:** ![pavithrakc](https://avatars.discourse-cdn.com/v4/letter/p/a6a055/32.png) [@pavithrakc](https://discuss.elastic.co/u/pavithrakc)\
**Post date:** [April 30, 2018, 8:37pm UTC](https://discuss.elastic.co/t/discover-tab-filters-data-incorrectly/130040/4 "2018-04-30T20:37:34Z")

</div>

Hello LeeDr,

Please find the attached snapshot of it.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/0/5076de8e17e53fe45ed61af2d6161e06c13eb641.png)

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [May 2, 2018, 1:16pm UTC](https://discuss.elastic.co/t/discover-tab-filters-data-incorrectly/130040/5 "2018-05-02T13:16:21Z")

</div>

> [@pavithrakc](#):
>
> Recent version 6.2.2 use time-based indices and other one 5.6.2 use normal index.

The index in Elasticsearch doesn't know if it's `time-based` or not. It's just data. It's Kibana that let's you decide if you specify a time field when you create the index pattern. If you select a time field for the index pattern then Discover can show the Date Histogram.

On your 6.2.2 instance, can you disable that filter and use the query bar to query `TRADENUMBER:615160670` and tell us if that gives the correct results?

---

<div class="post-metadata">

**Author:** ![pavithrakc](https://avatars.discourse-cdn.com/v4/letter/p/a6a055/32.png) [@pavithrakc](https://discuss.elastic.co/u/pavithrakc)\
**Post date:** [May 2, 2018, 2:13pm UTC](https://discuss.elastic.co/t/discover-tab-filters-data-incorrectly/130040/6 "2018-05-02T14:13:56Z")

</div>

> [@LeeDr](#):
>
> 615160670

I removed time filter and selected index of this month. It is not yielding correct results. Please see the below screenshot.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/9/19300a22ec2be14618466556d98ee010bbd48834.png)

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [May 2, 2018, 2:59pm UTC](https://discuss.elastic.co/t/discover-tab-filters-data-incorrectly/130040/7 "2018-05-02T14:59:01Z")

</div>

I suspect `TRADENUMBER` may be mapped incorrectly in some indices. Could you share the output of these requests:

`GET _field_caps?fields=TRADENUMBER`

`GET twofour_volume-*/_mapping/_doc/field/TRADENUMBER`

---

<div class="post-metadata">

**Author:** ![pavithrakc](https://avatars.discourse-cdn.com/v4/letter/p/a6a055/32.png) [@pavithrakc](https://discuss.elastic.co/u/pavithrakc)\
**Post date:** [May 2, 2018, 3:02pm UTC](https://discuss.elastic.co/t/discover-tab-filters-data-incorrectly/130040/8 "2018-05-02T15:02:07Z")

</div>

> [@Bargs](#):
>
> GET twofour\_volume-\*/\_mapping/\_doc/field/TRADENUMBER

Hello Matt,

Please find the attached output for the same:

1. GET \_field\_caps?fields=TRADENUMBER  
{  
"fields": {  
"TRADENUMBER": {  
"float": {  
"type": "float",  
"searchable": true,  
"aggregatable": true,  
"indices": [  
"twofour\_markup-2014.04",  
"twofour\_markup-2014.05",  
"twofour\_markup-2014.06",  
"twofour\_markup-2014.07",  
"twofour\_markup-2014.08",  
"twofour\_markup-2014.09",  
"twofour\_markup-2014.10",  
"twofour\_markup-2014.11",  
"twofour\_markup-2014.12",  
"twofour\_markup-2015.01",  
"twofour\_markup-2015.02",  
"twofour\_markup-2015.03",  
"twofour\_markup-2015.04",  
"twofour\_markup-2015.05",  
"twofour\_markup-2015.06",  
"twofour\_markup-2015.07",  
"twofour\_markup-2015.08",  
"twofour\_markup-2015.09",  
"twofour\_markup-2015.10",  
"twofour\_markup-2015.11",  
"twofour\_markup-2015.12",  
"twofour\_markup-2016.01",  
"twofour\_markup-2016.02",  
"twofour\_markup-2016.03",  
"twofour\_markup-2016.04",  
"twofour\_markup-2016.05",  
"twofour\_markup-2016.06",  
"twofour\_markup-2016.07",  
"twofour\_markup-2016.08",  
"twofour\_markup-2016.09",  
"twofour\_markup-2016.10",  
"twofour\_markup-2016.11",  
"twofour\_markup-2016.12",  
"twofour\_markup-2017.01",  
"twofour\_markup-2017.02",  
"twofour\_markup-2017.03",  
"twofour\_markup-2017.04",  
"twofour\_markup-2017.05",  
"twofour\_markup-2017.06",  
"twofour\_markup-2017.07",  
"twofour\_markup-2017.08",  
"twofour\_markup-2017.09",  
"twofour\_markup-2017.10",  
"twofour\_markup-2017.11",  
"twofour\_markup-2017.12",  
"twofour\_markup-2018.01",  
"twofour\_markup-2018.02",  
"twofour\_markup-2018.03",  
"twofour\_markup-2018.04",  
"twofour\_markup-2018.05",  
"twofour\_volume-2014.04",  
"twofour\_volume-2014.05",  
"twofour\_volume-2014.06",  
"twofour\_volume-2014.07",  
"twofour\_volume-2014.08",  
"twofour\_volume-2014.09",  
"twofour\_volume-2014.10",  
"twofour\_volume-2014.11",  
"twofour\_volume-2014.12",  
"twofour\_volume-2015.01",  
"twofour\_volume-2015.02",  
"twofour\_volume-2015.03",  
"twofour\_volume-2015.04",  
"twofour\_volume-2015.05",  
"twofour\_volume-2015.06",  
"twofour\_volume-2015.07",  
"twofour\_volume-2015.08",  
"twofour\_volume-2015.09",  
"twofour\_volume-2015.10",  
"twofour\_volume-2015.11",  
"twofour\_volume-2015.12",  
"twofour\_volume-2016.01",  
"twofour\_volume-2016.02",  
"twofour\_volume-2016.03",  
"twofour\_volume-2016.04",  
"twofour\_volume-2016.05",  
"twofour\_volume-2016.06",  
"twofour\_volume-2016.07",  
"twofour\_volume-2016.08",  
"twofour\_volume-2016.09",  
"twofour\_volume-2016.10",  
"twofour\_volume-2016.11",  
"twofour\_volume-2016.12",  
"twofour\_volume-2017.01",  
"twofour\_volume-2017.02",  
"twofour\_volume-2017.03",  
"twofour\_volume-2017.04",  
"twofour\_volume-2017.05",  
"twofour\_volume-2017.06",  
"twofour\_volume-2017.07",  
"twofour\_volume-2017.08",  
"twofour\_volume-2017.09",  
"twofour\_volume-2017.10",  
"twofour\_volume-2017.11",  
"twofour\_volume-2017.12",  
"twofour\_volume-2018.01",  
"twofour\_volume-2018.02",  
"twofour\_volume-2018.03",  
"twofour\_volume-2018.04",  
"twofour\_volume-2018.05"  
]  
},  
"long": {  
"type": "long",  
"searchable": true,  
"aggregatable": true,  
"indices": [  
"twofour\_trades-2017.08",  
"twofour\_trades-2017.09",  
"twofour\_trades-2018.01",  
"twofour\_trades-2018.04",  
"twofour\_trades-2018.05"  
]  
}  
}  
}  
}

2. GET twofour\_volume-\*/\_mapping/\_doc/field/TRADENUMBER

{}

It is empty.  
I did the following query.  
GET twofour\_volume-\*/\_mapping/field/TRADENUMBER

```
https://gist.github.com/pavithrachandrakasu/306330b8f6377cacb5841ab8d5720a3a

```

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [May 2, 2018, 7:52pm UTC](https://discuss.elastic.co/t/discover-tab-filters-data-incorrectly/130040/9 "2018-05-02T19:52:27Z")

</div>

Hmmm, I don't see anything out of the ordinary there. Could you try the [Explain API](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/search-explain.html) on one of the incorrectly matching docs with the query from the filter?

---

<div class="post-metadata">

**Author:** ![pavithrakc](https://avatars.discourse-cdn.com/v4/letter/p/a6a055/32.png) [@pavithrakc](https://discuss.elastic.co/u/pavithrakc)\
**Post date:** [May 2, 2018, 9:04pm UTC](https://discuss.elastic.co/t/discover-tab-filters-data-incorrectly/130040/10 "2018-05-02T21:04:48Z")

</div>

I do not find an option like \_doc inside. Please the below screenshot:

![image](https://us1.discourse-cdn.com/elastic/original/3X/d/6/d6282ffdcc2470221fb13bad01da69f2af7d9a96.png)

---

<div class="post-metadata">

**Author:** ![pavithrakc](https://avatars.discourse-cdn.com/v4/letter/p/a6a055/32.png) [@pavithrakc](https://discuss.elastic.co/u/pavithrakc)\
**Post date:** [May 2, 2018, 9:12pm UTC](https://discuss.elastic.co/t/discover-tab-filters-data-incorrectly/130040/11 "2018-05-02T21:12:25Z")

</div>

I just did something like below to find out how to use explain parameter:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/3/33923243ef2ed9234b4f7cd77f2c0017fa052fc7.png)

From above query, I took "\_type", "\_id" in the below query to find out.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/6/a69c79ee5ded218acebd2fe375174bf9a697283d.png)

I am not sure whether it is right or not. I am just sending it to you. I see that the details part is completely empty.

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [May 2, 2018, 9:55pm UTC](https://discuss.elastic.co/t/discover-tab-filters-data-incorrectly/130040/12 "2018-05-02T21:55:53Z")

</div>

The IDs of the docs in those two screenshots are different. Could you post the search hit for the doc that you're doing the `_explain` on in the second screenshot? Also, in your search request, please request the doc\_values for the TRADENUMBER field. You can do that like this:

```auto
GET /<index-name>/_search
{
    "query" : {
        "term": {
          "TRADENUMBER": 615160640
        }
    },
    "docvalue_fields" : ["TRADENUMBER"]
}

```

---

<div class="post-metadata">

**Author:** ![pavithrakc](https://avatars.discourse-cdn.com/v4/letter/p/a6a055/32.png) [@pavithrakc](https://discuss.elastic.co/u/pavithrakc)\
**Post date:** [May 2, 2018, 10:36pm UTC](https://discuss.elastic.co/t/discover-tab-filters-data-incorrectly/130040/13 "2018-05-02T22:36:20Z")

</div>

Sorry. I used a wrong ID. Now please refer to the below image:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/b/ebbc6552e34b02e4881a0dc85dbeab304b67efd1.png)

I think the results are same.

Please find the results of other query:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/8/5848fda1ac5561f5601921f7a6306aa78ee72866.png)

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [May 8, 2018, 4:08pm UTC](https://discuss.elastic.co/t/discover-tab-filters-data-incorrectly/130040/14 "2018-05-08T16:08:38Z")

</div>

Hi @pavithrakc, I checked with the ES team and it seems I missed the obvious. As you can see in your last screenshot, the value in `_source` and the `doc_values` (same as the indexed value you're searching on) are different. Since `TRADENUMBER` is mapped as a float in this index this is likely a floating point rounding issue. The largest whole integer a float can store without loss of precision is `16,777,217`, and your value is larger than that.

You can fix this by mapping the field as a different type. You have a few options with different tradeoffs.

If you don't actually need these to be floating point numbers you could map them as `keyword` or `long`. Keywords will be faster if you tend to do single point lookups on this field, longs will be faster if you tend to do more range queries.

If you do need these to be floating point numbers, you could change it to a `double` which supports larger numbers, or a `scaled float` which gives you control over the level of precision needed.

You can read more about the numerical datatypes available in ES [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/number.html).

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [May 9, 2018, 1:17pm UTC](https://discuss.elastic.co/t/discover-tab-filters-data-incorrectly/130040/15 "2018-05-09T13:17:25Z")

</div>

Now I see that the clue I missed from the very first screenshot is that all the TRADENUMBER values shown by that Discover filter are within a few numbers of each other. If you round them down to 7 or 8 digits they are all the same. Indicating the loss of precision.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 6, 2018, 1:17pm UTC](https://discuss.elastic.co/t/discover-tab-filters-data-incorrectly/130040/16 "2018-06-06T13:17:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
