# Facet returns different total at different times with the latest 0.90 release

**URL:** <https://discuss.elastic.co/t/facet-returns-different-total-at-different-times-with-the-latest-0-90-release/12112>\
**Category:** Elasticsearch\
**Created:** [May 24, 2013, 12:20pm UTC](https://discuss.elastic.co/t/facet-returns-different-total-at-different-times-with-the-latest-0-90-release/12112 "2013-05-24T12:20:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Manish](https://avatars.discourse-cdn.com/v4/letter/m/a6a055/32.png) [@Manish](https://discuss.elastic.co/u/Manish)\
**Post date:** [May 24, 2013, 12:20pm UTC](https://discuss.elastic.co/t/facet-returns-different-total-at-different-times-with-the-latest-0-90-release/12112/1 "2013-05-24T12:20:19Z")

</div>

Hello,

I have a strange problem. My query returns different results at different  
times.  
The query:  
curl -XPOST localhost:9200/content/bb/\_seach?pretty=1 -d '  
{"query":{"match\_all":{}},"facets":{"facet":{"terms":{"field":"country","size":10000,"order":"term"}}}}'

on the first go returns:

...  
...  
"facets" : {  
"facet" : {  
"\_type" : "terms",  
"missing" : 0,

- 

```
 "total" : 7256,*
"other" : 0,
"terms" : [ {
  "term" : "albania",
  "count" : 1
}, {
  "term" : "argentina",
  "count" : 4

```

...  
...  
On the second go, the same query returns:  
...  
...  
"facets" : {  
"facet" : {  
"\_type" : "terms",  
"missing" : 0,

- 

```
 "total" : 6948,*
"other" : 0,
"terms" : [ {
  "term" : "albania",
  "count" : 1
}, {
  "term" : "argentina",
  "count" : 4

```

...  
...

Please note the difference in the "total". Down the lines in the results, I  
find differences in numbers for individual countries. I am not sure why. My  
index is defined as:  
Analyzer -  
{  
"index": {  
"analysis": {  
"analyzer": {  
"string\_lowercase": {  
"type": "custom",  
"tokenizer": "keyword",  
"filter": "lowercase"  
}  
}  
}  
}  
}

_Mapping -_

```
"bb" : {
    "properties" : {
        "content": {
            "type": "object",
            "properties":{
                "centroid":{
                    "type":"geo_point"
                  },
                 "categoryID": {
                       "type" : "string",
                       "index" : "not_analyzed"
                 },
            "address":{
                "type":"object",
                "properties":{
                    "country":{
                        "type":"string",
                        "analyzer": "string_lowercase"
                        },
                     "city":{
                        "type":"string",
                        "analyzer": "string_lowercase"
                        },
                    "postalCode":{
                        "type":"string",
                        "analyzer": "string_lowercase"
                        },
                   "houseNumber":{
                        "type":"string"
                        }
                    }
                }    
            }
        }        
    }
}

```

}

Any ideas why I get different results for the same query at different times?  
The elasticsearch cluster is having two nodes running in Amazon Web Service.

thanks a lot for your help  
Best,  
Manish

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Dan\_Fairs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dan_fairs/32/1205_2.png) [@Dan\_Fairs](https://discuss.elastic.co/u/Dan_Fairs)\
**Post date:** [May 24, 2013, 6:10pm UTC](https://discuss.elastic.co/t/facet-returns-different-total-at-different-times-with-the-latest-0-90-release/12112/2 "2013-05-24T18:10:43Z")

</div>

Hi Manish,

On 24 May 2013, at 13:20, Manish Singh [singhmanishp@gmail.com](mailto:singhmanishp@gmail.com) wrote:

> Hello,
> 
> I have a strange problem. My query returns different results at different times.  
> The query:  
> curl -XPOST localhost:9200/content/bb/\_seach?pretty=1 -d '  
> {"query":{"match\_all":{}},"facets":{"facet":{"terms":{"field":"country","size":10000,"order":"term"}}}}'
> 
> on the first go returns:
> 
> ...  
> ...  
> "facets" : {  
> "facet" : {  
> "\_type" : "terms",  
> "missing" : 0,  
> "total" : 7256,  
> "other" : 0,  
> "terms" : [ {  
> "term" : "albania",  
> "count" : 1  
> }, {  
> "term" : "argentina",  
> "count" : 4  
> ...  
> ...  
> On the second go, the same query returns:  
> ...  
> ...  
> "facets" : {  
> "facet" : {  
> "\_type" : "terms",  
> "missing" : 0,  
> "total" : 6948,  
> "other" : 0,  
> "terms" : [ {  
> "term" : "albania",  
> "count" : 1  
> }, {  
> "term" : "argentina",  
> "count" : 4  
> ...  
> ...
> 
> Please note the difference in the "total". Down the lines in the results, I find differences in numbers for individual countries. I am not sure why. My index is defined as:  
> Analyzer -  
> {  
> "index": {  
> "analysis": {  
> "analyzer": {  
> "string\_lowercase": {  
> "type": "custom",  
> "tokenizer": "keyword",  
> "filter": "lowercase"  
> }  
> }  
> }  
> }  
> }
> 
> Mapping -
> 
> ```
> "bb" : {
> "properties" : {
> "content": {
> "type": "object",
> "properties":{
> "centroid":{
> "type":"geo_point"
> },
> "categoryID": {
> "type" : "string",
> "index" : "not_analyzed"
> },
> "address":{
> "type":"object",
> "properties":{
> "country":{
> "type":"string",
> "analyzer": "string_lowercase"
> },
> "city":{
> "type":"string",
> "analyzer": "string_lowercase"
> },
> "postalCode":{
> "type":"string",
> "analyzer": "string_lowercase"
> },
> "houseNumber":{
> "type":"string"
> }
> }
> }    
> }
> }        
> }
> }
> 
> ```
> 
> }
> 
> Any ideas why I get different results for the same query at different times?  
> The elasticsearch cluster is having two nodes running in Amazon Web Service.

Could it be possible that you're running into:

[https://github.com/elasticsearch/elasticsearch/issues/1305](https://github.com/elasticsearch/elasticsearch/issues/1305)

How many shards are in your index?

Cheers,  
Dan

--  
Dan Fairs | [dan.fairs@gmail.com](mailto:dan.fairs@gmail.com) | @danfairs | [secondsync.com](http://secondsync.com)

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Manish](https://avatars.discourse-cdn.com/v4/letter/m/a6a055/32.png) [@Manish](https://discuss.elastic.co/u/Manish)\
**Post date:** [May 27, 2013, 7:59am UTC](https://discuss.elastic.co/t/facet-returns-different-total-at-different-times-with-the-latest-0-90-release/12112/3 "2013-05-27T07:59:06Z")

</div>

Hi Dan,

I have 5 shards in my index. I did not experience the problem with the  
older version of the elasticsearch 0.20.5.

Is there any other workaround other then recreating the index with 1 shard?

Cheers,  
Manish

On Fri, May 24, 2013 at 9:10 PM, Dan Fairs [dan.fairs@gmail.com](mailto:dan.fairs@gmail.com) wrote:

> Hi Manish,
> 
> On 24 May 2013, at 13:20, Manish Singh [singhmanishp@gmail.com](mailto:singhmanishp@gmail.com) wrote:
> 
> Hello,
> 
> I have a strange problem. My query returns different results at different  
> times.  
> The query:  
> curl -XPOST localhost:9200/content/bb/\_seach?pretty=1 -d '
> 
> {"query":{"match\_all":{}},"facets":{"facet":{"terms":{"field":"country","size":10000,"order":"term"}}}}'
> 
> on the first go returns:
> 
> ...  
> ...  
> "facets" : {  
> "facet" : {  
> "\_type" : "terms",  
> "missing" : 0,
> 
> - 
> 
> ```
> "total" : 7256,*
> "other" : 0,
> "terms" : [ {
> "term" : "albania",
> "count" : 1
> }, {
> "term" : "argentina",
> "count" : 4
> 
> ```
> 
> ...  
> ...  
> On the second go, the same query returns:  
> ...  
> ...  
> "facets" : {  
> "facet" : {  
> "\_type" : "terms",  
> "missing" : 0,
> 
> - 
> 
> ```
> "total" : 6948,*
> "other" : 0,
> "terms" : [ {
> "term" : "albania",
> "count" : 1
> }, {
> "term" : "argentina",
> "count" : 4
> 
> ```
> 
> ...  
> ...
> 
> Please note the difference in the "total". Down the lines in the results,  
> I find differences in numbers for individual countries. I am not sure why.  
> My index is defined as:  
> Analyzer -  
> {  
> "index": {  
> "analysis": {  
> "analyzer": {  
> "string\_lowercase": {  
> "type": "custom",  
> "tokenizer": "keyword",  
> "filter": "lowercase"  
> }  
> }  
> }  
> }  
> }
> 
> _Mapping -_
> 
> ```
> "bb" : {
> "properties" : {
> "content": {
> "type": "object",
> "properties":{
> "centroid":{
> "type":"geo_point"
> },
> "categoryID": {
> "type" : "string",
> "index" : "not_analyzed"
> },
> "address":{
> "type":"object",
> "properties":{
> "country":{
> "type":"string",
> "analyzer": "string_lowercase"
> },
> "city":{
> "type":"string",
> "analyzer": "string_lowercase"
> },
> "postalCode":{
> "type":"string",
> "analyzer": "string_lowercase"
> },
> "houseNumber":{
> "type":"string"
> }
> }
> }
> }
> }
> }
> }
> 
> ```
> 
> }
> 
> Any ideas why I get different results for the same query at different  
> times?  
> The elasticsearch cluster is having two nodes running in Amazon Web  
> Service.
> 
> Could it be possible that you're running into:
> 
> [terms facet gives wrong count with n\_shards \> 1 · Issue #1305 · elastic/elasticsearch · GitHub](https://github.com/elasticsearch/elasticsearch/issues/1305)
> 
> How many shards are in your index?
> 
> Cheers,  
> Dan
> 
> --  
> Dan Fairs | [dan.fairs@gmail.com](mailto:dan.fairs@gmail.com) | @danfairs | [secondsync.com](http://secondsync.com)
> 
> --  
> You received this message because you are subscribed to a topic in the  
> Google Groups "elasticsearch" group.  
> To unsubscribe from this topic, visit  
> [https://groups.google.com/d/topic/elasticsearch/qq9-27vOkrY/unsubscribe?hl=en-US](https://groups.google.com/d/topic/elasticsearch/qq9-27vOkrY/unsubscribe?hl=en-US)  
> .  
> To unsubscribe from this group and all its topics, send an email to  
> [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Dan\_Fairs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dan_fairs/32/1205_2.png) [@Dan\_Fairs](https://discuss.elastic.co/u/Dan_Fairs)\
**Post date:** [May 27, 2013, 4:58pm UTC](https://discuss.elastic.co/t/facet-returns-different-total-at-different-times-with-the-latest-0-90-release/12112/4 "2013-05-27T16:58:00Z")

</div>

Hi Manish,

> Hi Dan,
> 
> I have 5 shards in my index. I did not experience the problem with the older version of the elasticsearch 0.20.5.
> 
> Is there any other workaround other then recreating the index with 1 shard?

The workaround suggested by Shay (I can't remember if it's in that issue, or whether it was in related discussion on the mailing list) was to increase the size parameter in your facet - multiply it by the number of shards, basically. So, in your example below, you'd ask for a size of 50,000 rather than 10,000, assuming 5 shards.

We've been using the 1-shard workaround to date. It's worked OK for us, but we do have time-based data (so a new index every week) and a relatively small cluster. If you aren't regularly creating new indices, or your cluster has relatively few nodes (so you'll end up with hotspots for indexing/search) then you'll probably want to try the facet size workaround.

If those don't work for you, then maybe you're not experiencing the problem described in the issue! (Especially as it used to work OK... we're still on 0.19.8).

Cheers,  
Dan

> Cheers,  
> Manish
> 
> On Fri, May 24, 2013 at 9:10 PM, Dan Fairs [dan.fairs@gmail.com](mailto:dan.fairs@gmail.com) wrote:  
> Hi Manish,
> 
> On 24 May 2013, at 13:20, Manish Singh [singhmanishp@gmail.com](mailto:singhmanishp@gmail.com) wrote:
> 
> > Hello,
> > 
> > I have a strange problem. My query returns different results at different times.  
> > The query:  
> > curl -XPOST localhost:9200/content/bb/\_seach?pretty=1 -d '  
> > {"query":{"match\_all":{}},"facets":{"facet":{"terms":{"field":"country","size":10000,"order":"term"}}}}'
> > 
> > on the first go returns:
> > 
> > ...  
> > ...  
> > "facets" : {  
> > "facet" : {  
> > "\_type" : "terms",  
> > "missing" : 0,  
> > "total" : 7256,  
> > "other" : 0,  
> > "terms" : [ {  
> > "term" : "albania",  
> > "count" : 1  
> > }, {  
> > "term" : "argentina",  
> > "count" : 4  
> > ...  
> > ...  
> > On the second go, the same query returns:  
> > ...  
> > ...  
> > "facets" : {  
> > "facet" : {  
> > "\_type" : "terms",  
> > "missing" : 0,  
> > "total" : 6948,  
> > "other" : 0,  
> > "terms" : [ {  
> > "term" : "albania",  
> > "count" : 1  
> > }, {  
> > "term" : "argentina",  
> > "count" : 4  
> > ...  
> > ...
> > 
> > Please note the difference in the "total". Down the lines in the results, I find differences in numbers for individual countries. I am not sure why. My index is defined as:  
> > Analyzer -  
> > {  
> > "index": {  
> > "analysis": {  
> > "analyzer": {  
> > "string\_lowercase": {  
> > "type": "custom",  
> > "tokenizer": "keyword",  
> > "filter": "lowercase"  
> > }  
> > }  
> > }  
> > }  
> > }
> > 
> > Mapping -
> > 
> > ```
> > "bb" : {
> > "properties" : {
> > "content": {
> > "type": "object",
> > "properties":{
> > "centroid":{
> > "type":"geo_point"
> > },
> > "categoryID": {
> > "type" : "string",
> > "index" : "not_analyzed"
> > },
> > "address":{
> > "type":"object",
> > "properties":{
> > "country":{
> > "type":"string",
> > "analyzer": "string_lowercase"
> > },
> > "city":{
> > "type":"string",
> > "analyzer": "string_lowercase"
> > },
> > "postalCode":{
> > "type":"string",
> > "analyzer": "string_lowercase"
> > },
> > "houseNumber":{
> > "type":"string"
> > }
> > }
> > }    
> > }
> > }        
> > }
> > }
> > 
> > ```
> > 
> > }
> > 
> > Any ideas why I get different results for the same query at different times?  
> > The elasticsearch cluster is having two nodes running in Amazon Web Service.
> 
> Could it be possible that you're running into:
> 
> [https://github.com/elasticsearch/elasticsearch/issues/1305](https://github.com/elasticsearch/elasticsearch/issues/1305)
> 
> How many shards are in your index?
> 
> Cheers,  
> Dan
> 
> --  
> Dan Fairs | [dan.fairs@gmail.com](mailto:dan.fairs@gmail.com) | @danfairs | [secondsync.com](http://secondsync.com)
> 
> --  
> You received this message because you are subscribed to a topic in the Google Groups "elasticsearch" group.  
> To unsubscribe from this topic, visit [https://groups.google.com/d/topic/elasticsearch/qq9-27vOkrY/unsubscribe?hl=en-US](https://groups.google.com/d/topic/elasticsearch/qq9-27vOkrY/unsubscribe?hl=en-US).  
> To unsubscribe from this group and all its topics, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
Dan Fairs | [dan.fairs@gmail.com](mailto:dan.fairs@gmail.com) | @danfairs | [secondsync.com](http://secondsync.com)

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:34am UTC](https://discuss.elastic.co/t/facet-returns-different-total-at-different-times-with-the-latest-0-90-release/12112/5 "2017-07-06T02:34:31Z")

</div>


