# Elasticsearch 2.1.2 after update , unexpected result

**URL:** <https://discuss.elastic.co/t/elasticsearch-2-1-2-after-update-unexpected-result/178853>\
**Category:** Elasticsearch\
**Created:** [April 29, 2019, 7:34am UTC](https://discuss.elastic.co/t/elasticsearch-2-1-2-after-update-unexpected-result/178853 "2019-04-29T07:34:31Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sshling](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sshling/32/24052_2.png) [@sshling](https://discuss.elastic.co/u/sshling)\
**Post date:** [April 29, 2019, 7:34am UTC](https://discuss.elastic.co/t/elasticsearch-2-1-2-after-update-unexpected-result/178853/1 "2019-04-29T07:34:31Z")

</div>

```auto
GET cross_dms_receive_send_diff/cross_dms_receive_send_diff/_search
{
    "query": {
      "bool": {
        "must": [
          {
            "term": {
              "waybill_code": "VD52794532626"
            }
          },
          {
            "range": {
              "inspect_time": {
                "gt": "1556294400000", // 2019/4/27 0:0:0
                "lt": "1556467199000" // 2019/4/28 23:59:59
              }
            }
          }
        ]
      }
    },
    "aggs": {
      "inspect_time": {
        "terms": {
          "field": "inspect_time"
        }
      }
    }
  }

 {
  "_shards": {
    "total": 32,
    "failed": 0,
    "successful": 32
  },
  "hits": {
    "hits": [
      {
        "_index": "cross_dms_receive_send_diff",
        "_type": "cross_dms_receive_send_diff",
        "_source": {
          "waybill_code": "VD52794532626",
          "inspect_time": 1553966138000 // 1. 2019/3/31 1:15:38
        },
        "_id": "VD52794532626-1-1-|1086",
        "_score": 17.218697
      }
    ],
    "total": 1,
    "max_score": 17.218697
  },
  "took": 12,
  "timed_out": false,
  "aggregations": {
    "inspect_time": {
      "doc_count_error_upper_bound": 0,
      "sum_other_doc_count": 0,
      "buckets": [
        {
          "key_as_string": "2019-03-30T17:15:38.000Z",// 2.
          "doc_count": 1,
          "key": 1553966138000 
        },
        {
          "key_as_string": "2019-04-27T02:51:50.000Z",//3.
          "doc_count": 1,
          "key": 1556333510000
        }
      ]
    }
  }
}

```

This is the production environment, the test environment cannot be reproduced。  
one document after update operation , looks like there are 2 indices .  
one for old ,another for new ,but the `_source` is old .

```auto
"_id": "VD52794532626-1-1-|1086"
"key_as_string": "2019-03-30T17:15:38.000Z"// 2. first index the doc  
"key_as_string": "2019-04-27T02:51:50.000Z",//3. update...

```

Many of the data updated during this time are like this(wrong), and after one day , the subsequent update operations are normal. No operation during this period

**General speeking ,the result of the aggregation should be a bucket, not the two here.**

How to explain this? How to avoid the next occurrence？

The doc field `inspect_time` mapping:

```auto
"inspect_time": {
    "format": "strict_date_optional_time||epoch_millis",
    "type": "date"
}

```

Thank you for your help。

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 29, 2019, 7:37am UTC](https://discuss.elastic.co/t/elasticsearch-2-1-2-after-update-unexpected-result/178853/2 "2019-04-29T07:37:44Z")

</div>

It's not really clear what you are asking or what you problem is sorry. Are you able to provide more information?

---

<div class="post-metadata">

**Author:** ![sshling](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sshling/32/24052_2.png) [@sshling](https://discuss.elastic.co/u/sshling)\
**Post date:** [April 29, 2019, 7:45am UTC](https://discuss.elastic.co/t/elasticsearch-2-1-2-after-update-unexpected-result/178853/3 "2019-04-29T07:45:07Z")

</div>

@warkolm

I added some descriptions, please help me find it again.

```auto
GET cross_dms_receive_send_diff/cross_dms_receive_send_diff/_search
{
  "query": {
    "bool": {
      "must": [
        {
          "term": {
            "waybill_code": "VD52794532626"
          }
        },
        {
          "range": {
            "inspect_time": {
              "gt": "1556294400000", // 2019/4/27 0:0:0
              "lt": "1556467199000" // 2019/4/28 23:59:59
            }
          }
        }
      ]
    }
  }
}

{
  "_shards": {
    "total": 32,
    "failed": 0,
    "successful": 32
  },
  "hits": {
    "hits": [
      {
        "_index": "cross_dms_receive_send_diff",
        "_type": "cross_dms_receive_send_diff",
        "_source": {
          "waybill_code": "VD52794532626",
          "inspect_time": 1553966138000 //2019/3/31 1:15:38
        },
        "_id": "VD52794532626-1-1-|1086",
        "_score": 17.219076
      }
    ],
    "total": 1,
    "max_score": 17.219076
  },
  "took": 117,
  "timed_out": false
}

```

Initially found the problem,the result does not match the query criteria。

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 29, 2019, 9:19am UTC](https://discuss.elastic.co/t/elasticsearch-2-1-2-after-update-unexpected-result/178853/4 "2019-04-29T09:19:52Z")

</div>

Some comments:

- Use `_doc` instead of `cross_dms_receive_send_diff` type name. Type are going to be removed in the future.
- Depending on the `waybill_code` mapping, your `term` query with `VD52794532626` may not match.
- in the future please provide a full recreation script as described in [About the Elasticsearch category](https://discuss.elastic.co/t/about-the-elasticsearch-category/21). It will help to better understand what you are doing. Please, try to keep the example as simple as possible.

A full reproduction script will help readers to understand, reproduce and if needed fix your problem. It will also most likely help to get a faster answer.

---

<div class="post-metadata">

**Author:** ![sshling](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sshling/32/24052_2.png) [@sshling](https://discuss.elastic.co/u/sshling)\
**Post date:** [April 29, 2019, 11:07am UTC](https://discuss.elastic.co/t/elasticsearch-2-1-2-after-update-unexpected-result/178853/5 "2019-04-29T11:07:06Z")

</div>

- Use `_doc` , i know ,but it's old cluster ,so next upgrade will change
- the problem not about `waybill_code` , It appears here, just to facilitate filtering out specific data from massive data. the problem is `inspect_time` , another example maybe help you understand
- This is an accident in the production environment, it can't be reproduced. If it can be reproduced, I will track the code debugging. I want to know under what circumstances this possibility problem will occur, or after Elasticsearch version 2.1.2 has fixed related bugs.

```auto
   .... the query same as previous , omitted here 
    "aggs": {
      "inspect_time": {
        "terms": {
          "field": "inspect_time"
        },
        "aggs": {
          "xx": {
            "top_hits": {
              "size": 2
            }
          }
        }
      }
    }

result:
    "aggregations": {
      "inspect_time": {
        "doc_count_error_upper_bound": 0,
        "sum_other_doc_count": 0,
        "buckets": [
          {
            "key_as_string": "2019-04-10T02:40:00.000Z", //key 1  
            "xx": {
              "hits": {
                "hits": [
                  {
                    "_index": "cross_dms_receive_send_diff",
                    "_type": "cross_dms_receive_send_diff",
                    "_source": {
                      "waybill_code": "85640578962",
                      "inspect_time": 1554864000000 //equal the key
                    },
                    "_id": "85640578962-1-1-002|1086",// doc id 1
                    "_score": 17.2106
                  }
                ],
                "total": 1,
                "max_score": 17.2106
              }
            },
            "doc_count": 1,
            "key": 1554864000000 //key 1
          },
          {
            "key_as_string": "2019-04-27T02:14:08.000Z", //key 2 
            "xx": {
              "hits": {
                "hits": [
                  {
                    "_source": {
                      "waybill_code": "85640578962",
                      "inspect_time": 1554864000000 // Note here: not equal the key
                    },
                    "_id": "85640578962-1-1-002|1086", //doc id 2 , the same id as last bucket .
                  }
                ],
                "total": 1,
                "max_score": 17.2106
              }
            },
            "doc_count": 1,
            "key": 1556331248000 //key 2
          }
        ]
      }
    }

```

 ![es](https://us1.discourse-cdn.com/elastic/original/3X/a/4/a46746da93382968db82d156ac893f44b011e528.jpeg)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 27, 2019, 11:07am UTC](https://discuss.elastic.co/t/elasticsearch-2-1-2-after-update-unexpected-result/178853/6 "2019-05-27T11:07:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
