# Help understanding "order by" metric

**URL:** <https://discuss.elastic.co/t/help-understanding-order-by-metric/97143>\
**Category:** Kibana\
**Created:** [August 15, 2017, 6:37pm UTC](https://discuss.elastic.co/t/help-understanding-order-by-metric/97143 "2017-08-15T18:37:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rmorris](https://avatars.discourse-cdn.com/v4/letter/r/9f8e36/32.png) [@rmorris](https://discuss.elastic.co/u/rmorris)\
**Post date:** [August 15, 2017, 6:37pm UTC](https://discuss.elastic.co/t/help-understanding-order-by-metric/97143/1 "2017-08-15T18:37:44Z")

</div>

Hi there, I've been tearing my hair out in an attempt to get a heatmap to behave exactly as I'd like.

My goal is to display the max timestamp for documents, grouped by a specific term. This appears to work well when I order the Y-axis by the term itself (i.e. alphabetically):

 ![order-by-term](https://us1.discourse-cdn.com/elastic/original/3X/8/7/87d8cccb768d21450c6a0277d121e8fc7aac7145.png)

But, I really want to order the Y-axis by the metric itself so that groups with a lower max timestamp appear at top of the heatmap. However, when I change the ordering to use the metric it appears to change the actual values that I'm seeing for any given group (see the highlighted row above and below - same bucket, different values), which is not what I'd expect from an "ordering function":

 ![order-by-metric](https://us1.discourse-cdn.com/elastic/original/3X/0/8/084aa0a0d5bc0959d481ab8a3d1e50700c0f4a92.png)

I'm sure this is a fundamental misunderstanding on my part but would really like to get to the bottom of it. Any help in explaining what I'm seeing would be greatly appreciated.

Thanks

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [August 16, 2017, 6:17pm UTC](https://discuss.elastic.co/t/help-understanding-order-by-metric/97143/2 "2017-08-16T18:17:13Z")

</div>

Hi Richie,

Don't feel bad. Some of these behavior can be pretty confusing. I _think_ the difference you're seeing in values is caused by some optimizations Elasticsearch does. If I understand it correctly, if the data in your gc-\* is split over multiple shards (which is the normal case) then the top 20 in your sort (either by Term of by Max timestamp) can be inaccurate as it's combined the results from each shard.

Read through the sort example here;  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html)

If you still want more info on the topic you might want to post in the Elasticsearch channel of the forums.

Thanks,  
Lee

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 13, 2017, 6:17pm UTC](https://discuss.elastic.co/t/help-understanding-order-by-metric/97143/3 "2017-09-13T18:17:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
