# Elastic dev tool has different total hits number than discover query search

**URL:** <https://discuss.elastic.co/t/elastic-dev-tool-has-different-total-hits-number-than-discover-query-search/344275>\
**Category:** Elasticsearch\
**Created:** [October 3, 2023, 4:08am UTC](https://discuss.elastic.co/t/elastic-dev-tool-has-different-total-hits-number-than-discover-query-search/344275 "2023-10-03T04:08:12Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![JasonREC](https://avatars.discourse-cdn.com/v4/letter/j/858c86/32.png) [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Post date:** [October 3, 2023, 4:08am UTC](https://discuss.elastic.co/t/elastic-dev-tool-has-different-total-hits-number-than-discover-query-search/344275/1 "2023-10-03T04:08:12Z")

</div>

Hi, I have the same query and with the same filter.

But the dev tool and discover give me different total hit counts ..I wonder what is the reason to that? and which is the accurate one

 ![dev-tool](https://us1.discourse-cdn.com/elastic/original/3X/6/2/623091f5745ffc8e5ea63e0c205461c523deef1d.png)  
 ![discover](https://us1.discourse-cdn.com/elastic/original/3X/e/d/ed714ac07828b74cd025e3cd85eb9f49996e2305.png)

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 3, 2023, 4:27am UTC](https://discuss.elastic.co/t/elastic-dev-tool-has-different-total-hits-number-than-discover-query-search/344275/2 "2023-10-03T04:27:08Z")

</div>

Maybe because of the timestamp values which are not identical?  
Or you are not in the GMT timezone so again the timestamp is different?

---

<div class="post-metadata">

**Author:** ![JasonREC](https://avatars.discourse-cdn.com/v4/letter/j/858c86/32.png) [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Post date:** [October 3, 2023, 4:30am UTC](https://discuss.elastic.co/t/elastic-dev-tool-has-different-total-hits-number-than-discover-query-search/344275/3 "2023-10-03T04:30:20Z")

</div>

Hi, @dadoonet,

Thanks for the reply.  
I think my Discover has the corret timeStamp to my local, is it possible to sync the dev tool timestamp to the Discover one so that it can be reflected in the time-zone

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 3, 2023, 4:59am UTC](https://discuss.elastic.co/t/elastic-dev-tool-has-different-total-hits-number-than-discover-query-search/344275/4 "2023-10-03T04:59:14Z")

</div>

Hi @JasonREC  
The time range is not the same pretty clear....

Your discover and query clearly show different time ranges...

If you put in _ **exactly** _ the same time range to the millisecond they should be the same, I have validated many times.

---

<div class="post-metadata">

**Author:** ![JasonREC](https://avatars.discourse-cdn.com/v4/letter/j/858c86/32.png) [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Post date:** [October 3, 2023, 6:34am UTC](https://discuss.elastic.co/t/elastic-dev-tool-has-different-total-hits-number-than-discover-query-search/344275/5 "2023-10-03T06:34:56Z")

</div>

Thanks @stephenb  
but what do you mean by put in _ **exactly** _ the same time range to the millisecond?

Currently, I am not sure if I want the hit number for the entire September, which one I should use...

 ![dev_tool](https://us1.discourse-cdn.com/elastic/original/3X/3/e/3e993ddcc3a624187f7b1d6c90ab2b9d8bb53e0d.png)  
 ![Screenshot 2023-10-03 142933](https://us1.discourse-cdn.com/elastic/original/3X/a/1/a14877ae9c144033f903e05f932fb63a9deb716e.png)

---

<div class="post-metadata">

**Author:** ![JasonREC](https://avatars.discourse-cdn.com/v4/letter/j/858c86/32.png) [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Post date:** [October 3, 2023, 9:34am UTC](https://discuss.elastic.co/t/elastic-dev-tool-has-different-total-hits-number-than-discover-query-search/344275/6 "2023-10-03T09:34:14Z")

</div>

@stephenb

I eventually use this date range in order to get all the document falls in the September. But there is still a bit different from the Kibana Discover

"range": {  
"date\_range": {  
"field": "@timestamp",  
"format": "yyyy-MM-dd HH:mm:ss.SSS",  
"ranges": [  
{  
"from": "2023-09-01 00:00:00.000",  
"to": "2023-09-30 23:59:59.999"  
}  
]  
}

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 3, 2023, 10:32am UTC](https://discuss.elastic.co/t/elastic-dev-tool-has-different-total-hits-number-than-discover-query-search/344275/7 "2023-10-03T10:32:31Z")

</div>

Please don't post images of text as they are hard to read, may not display correctly for everyone, and are not searchable.

Instead, paste the text and format it with `</>` icon or pairs of triple backticks (```), and check the preview window to make sure it's properly formatted before posting it. This makes it more likely that your question will receive a useful answer.

You can do this (Elastic 8.10.2). Click on Inspect and then choose the "Request" tab. You will see the exact query which is sent to Elasticsearch.

Click on Open in Console. And it should give you the same results.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/0/106b300908c92c018b4f2ea9d965b5c83c84cefc.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 3, 2023, 3:59pm UTC](https://discuss.elastic.co/t/elastic-dev-tool-has-different-total-hits-number-than-discover-query-search/344275/8 "2023-10-03T15:59:24Z")

</div>

Hi @JasonREC

My Sample, This is what I mean...

Discover

 ![Screenshot 2023-10-03 at 8.55.26 AM](https://us1.discourse-cdn.com/elastic/original/3X/2/6/26adea694b46c77f2aff02359dc3ebd7abbbcc0b.jpeg)

KQL:  
`kubernetes.labels.app : "productcatalogservice"`

Date Ranges  
`Oct 2, 2023 @ 00:00:00.000` \<!-- Exact Date  
`Oct 3, 2023 @ 00:00:00.000` \<!-- Exact Date

Inspect -\> Query

```auto
  "query": {
    "bool": {
      "must": [],
      "filter": [
        {
          "bool": {
            "should": [
              {
                "term": {
                  "kubernetes.labels.app": {
                    "value": "productcatalogservice"
                  }
                }
              }
            ],
            "minimum_should_match": 1
          }
        },
        {
          "range": {
            "@timestamp": {
              "format": "strict_date_optional_time",
              "gte": "2023-10-02T07:00:00.000Z", <!-- Exact Date 
              "lte": "2023-10-03T07:00:00.000Z" <!-- Exact Date 
            }
          }
        }
      ],
      "should": [],
      "must_not": []
    }
  },

```

Then I run in Dev Tools

```auto
GET logs-*/_search
{
 "size": 0,
 "track_total_hits": true,  
 "query": {
    "bool": {
      "must": [],
      "filter": [
        {
          "bool": {
            "should": [
              {
                "term": {
                  "kubernetes.labels.app": {
                    "value": "productcatalogservice"
                  }
                }
              }
            ],
            "minimum_should_match": 1
          }
        },
        {
          "range": {
            "@timestamp": {
              "format": "strict_date_optional_time",
              "gte": "2023-10-02T07:00:00.000Z", <!-- Exact Date 
              "lte": "2023-10-03T07:00:00.000Z" <!-- Exact Date 
            }
          }
        }
      ],
      "should": [],
      "must_not": []
    }
  }
}

```

# Result

```auto
{
  "took": 90,
  "timed_out": false,
  "_shards": {
    "total": 67,
    "successful": 67,
    "skipped": 0,
    "failed": 0
  },
  "hits": {
    "total": {
      "value": 4991548, <!-- Exact Same Answer 
      "relation": "eq"
    },
    "max_score": null,
    "hits": []
  }
}

```

Exactly the same

---

<div class="post-metadata">

**Author:** ![JasonREC](https://avatars.discourse-cdn.com/v4/letter/j/858c86/32.png) [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Post date:** [October 4, 2023, 2:17am UTC](https://discuss.elastic.co/t/elastic-dev-tool-has-different-total-hits-number-than-discover-query-search/344275/9 "2023-10-04T02:17:35Z")

</div>

Hi @stephenb

Thanks for the demo! very helpful!

I now found out the date range that I specify in the **Discover console** ` Sep 1 00:00:00 to Sep 30 23:59:59:999` is completely different from the query inside **inspect request**

Inside the inspect query, date range are

```auto
"gte": "2023-08-31T16:00:00.000Z",
"lte": "2023-09-30T16:00:00.000Z"

```

I am not sure why this happened but I think that is the reason that you mentioned which really cause the total hits number has different result.

In Discover:

 ![p1](https://us1.discourse-cdn.com/elastic/original/3X/9/e/9ed5e3f682aed7f0b6a82651a9e0b114d41b4084.png)

In inspect request query:

 ![p2](https://us1.discourse-cdn.com/elastic/original/3X/7/9/790e81573586b8f6ef255f83efd320362a56f833.png)

---

<div class="post-metadata">

**Author:** ![JasonREC](https://avatars.discourse-cdn.com/v4/letter/j/858c86/32.png) [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Post date:** [October 4, 2023, 2:22am UTC](https://discuss.elastic.co/t/elastic-dev-tool-has-different-total-hits-number-than-discover-query-search/344275/10 "2023-10-04T02:22:53Z")

</div>

Hi @dadoonet

I am sorry for the inconvenience, I will now take advantage of the `</>` icon !

And, thanks for the guide of taking me to the insepct reuqest tab , I now found out the reason which cause the total hit has different result from Discover and dev tool

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 1, 2023, 2:23am UTC](https://discuss.elastic.co/t/elastic-dev-tool-has-different-total-hits-number-than-discover-query-search/344275/11 "2023-11-01T02:23:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
