# Getting unusual data during aggregation and curation in Elasticsearch

**URL:** <https://discuss.elastic.co/t/getting-unusual-data-during-aggregation-and-curation-in-elasticsearch/310899>\
**Category:** Elasticsearch\
**Created:** [July 28, 2022, 3:41pm UTC](https://discuss.elastic.co/t/getting-unusual-data-during-aggregation-and-curation-in-elasticsearch/310899 "2022-07-28T15:41:28Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anika\_Sultana](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anika_sultana/32/100717_2.png) [@Anika\_Sultana](https://discuss.elastic.co/u/Anika_Sultana)\
**Post date:** [July 28, 2022, 3:41pm UTC](https://discuss.elastic.co/t/getting-unusual-data-during-aggregation-and-curation-in-elasticsearch/310899/1 "2022-07-28T15:41:28Z")

</div>

Hi,  
I am using **Elasticsearch 7.4**. I noticed some unexpected scenarios during data aggregation and data curation.  
Let me explain the scenario. I have 100 user\_id and among them are AA, AB, AC, and AD. Now if I try to aggregate those user\_id, I get some more extra data, such as BA, and BB.

> Please note those user\_id's start with `A` and `B`, they live in Cluster 1. And this issue arises when I started to migrate all data starting with `A` in the Cluster 2.

**The query I was using**

```auto
GET sturdent_data-2022*/_search
{
  "size": 0, 
  "query": {
    "bool": {
      "should": [
        {
          "match": {
            "user_id": "AA"
          }
        },
        {
          "match": {
            "user_id": "AB"
          }
        },
        {
          "match": {
            "user_id": "AC"
          }
        },
        {
          "match": {
            "user_id": "AD"
          }
        } ]
    }
  },
  "aggs": {
    "NAME": {
      "terms": {
        "field": "user_id.keyword",
        "size": 100
      }
    }
  }
}

```

**The output of the query is**

```auto
  "aggregations" : {
    "NAME" : {
      "doc_count_error_upper_bound" : 0,
      "sum_other_doc_count" : 0,
      "buckets" : [
        {
          "key" : "AA",
          "doc_count" : 98
        },
        {
          "key" : "AB",
          "doc_count" : 74
        },
        {
          "key" : "BA",
          "doc_count" : 68
        },
        {
          "key" : "AD",
          "doc_count" : 54
        },
        {
          "key" : "AC",
          "doc_count" : 35
        },
        {
          "key" : "BB",
          "doc_count" : 12
        }
      ]
    }
  }

```

In the output, I received user\_id `BA` and `BB` as extra unexpected data.  
The same thing happens during the curation using `_delete_by_query`.  
I found a solution during aggregation and that is use the `keyword` during data searching.

```auto
 {
          "match": {
            "user_id.keyword": "AD"
 }

```

But this does not work during curation, it removes all the data.

Now I need to get rid of these unexpected data during searching or data curation.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 28, 2022, 3:41pm UTC](https://discuss.elastic.co/t/getting-unusual-data-during-aggregation-and-curation-in-elasticsearch/310899/2 "2022-07-28T15:41:28Z")

</div>

Elasticsearch 7.4 is [EOL](https://www.elastic.co/support/eol) and no longer supported. Please upgrade ASAP.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 25, 2022, 3:41pm UTC](https://discuss.elastic.co/t/getting-unusual-data-during-aggregation-and-curation-in-elasticsearch/310899/3 "2022-08-25T15:41:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
