# Elasticsearch aggregation not matching with unique count metrics

**URL:** <https://discuss.elastic.co/t/elasticsearch-aggregation-not-matching-with-unique-count-metrics/109796>\
**Category:** Elasticsearch\
**Created:** [November 30, 2017, 4:27pm UTC](https://discuss.elastic.co/t/elasticsearch-aggregation-not-matching-with-unique-count-metrics/109796 "2017-11-30T16:27:58Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mormor1971](https://avatars.discourse-cdn.com/v4/letter/m/e56c9b/32.png) [@mormor1971](https://discuss.elastic.co/u/mormor1971)\
**Post date:** [November 30, 2017, 4:27pm UTC](https://discuss.elastic.co/t/elasticsearch-aggregation-not-matching-with-unique-count-metrics/109796/1 "2017-11-30T16:27:59Z")

</div>

Hello All,

I have a weird issue where if I have a large dataset with authentications against a nas device and I ask for a specific region with nas:xxxx\* and the authentications against that region I get two different results for the same filter and timeframe.

If I simply ask for unique users in region x I get 2478 unique users back, but if I then ask for those usernames with a sub aggregation I only get 2409 users back.

Why is that?

Which number is correct and why do I get different results when ask for a high-level unique user count and then when asking for the detailed user names I get less back?

The number of documents (a simple count metric) stays the same throughout so it's not because it's missing shards I think. All shards with this data range in have responded fine and there are no error counters in the responses.

Can anyone help me explain that please?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 30, 2017, 4:48pm UTC](https://discuss.elastic.co/t/elasticsearch-aggregation-not-matching-with-unique-count-metrics/109796/2 "2017-11-30T16:48:38Z")

</div>

The cardinality aggregation [returns an approximation](https://www.elastic.co/guide/en/elasticsearch/reference/6.0/search-aggregations-metrics-cardinality-aggregation.html#_counts_are_approximate), which probably is why you are seeing a discrepancy.

---

<div class="post-metadata">

**Author:** ![mormor1971](https://avatars.discourse-cdn.com/v4/letter/m/e56c9b/32.png) [@mormor1971](https://discuss.elastic.co/u/mormor1971)\
**Post date:** [December 1, 2017, 10:54am UTC](https://discuss.elastic.co/t/elasticsearch-aggregation-not-matching-with-unique-count-metrics/109796/3 "2017-12-01T10:54:04Z")

</div>

Hi Christian, thank you very much for getting back to me.

That's interesting to know, I wasn't aware that that was the case.

Do you know if there are any way of getting exact counts back for larger datasets outside of making a search for the data and then do the counts / cardinal aggregations myself in a script?

Unfortunately for me the datasets ate 9M authentications a month with that particular filter and I end up with 20k buckets which does tally up with what I expect and get back if I ask for the list of usernames.

Is that number correct?

I haven't made the script that will extract all of the authentications and then do my own aggregations yet though.

Is this 'approximation' only happening with cardinal aggregations , i.e. the metrics in your visualisations or is it across the board for all aggregations?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 1, 2017, 11:15am UTC](https://discuss.elastic.co/t/elasticsearch-aggregation-not-matching-with-unique-count-metrics/109796/4 "2017-12-01T11:15:39Z")

</div>

It only applies to some aggregations, but you can tune the accuracy through the [precision threshold](https://www.elastic.co/guide/en/elasticsearch/reference/6.0/search-aggregations-metrics-cardinality-aggregation.html#_precision_control). Depending on the cardinality of your field this may or may not give accurate results. Set it above your cardinality and see how it affects results.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 29, 2017, 11:16am UTC](https://discuss.elastic.co/t/elasticsearch-aggregation-not-matching-with-unique-count-metrics/109796/5 "2017-12-29T11:16:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
