# Impossible query response?

**URL:** <https://discuss.elastic.co/t/impossible-query-response/319236>\
**Category:** Elasticsearch\
**Created:** [November 17, 2022, 6:13pm UTC](https://discuss.elastic.co/t/impossible-query-response/319236 "2022-11-17T18:13:03Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![iamthealex1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iamthealex1/32/111669_2.png) [@iamthealex1](https://discuss.elastic.co/u/iamthealex1)\
**Post date:** [November 17, 2022, 6:13pm UTC](https://discuss.elastic.co/t/impossible-query-response/319236/1 "2022-11-17T18:13:03Z")

</div>

```auto
  POST /metricbeat-2022.11.17/_search
{
  "size": 2,
  "_source": ["system.process.cpu.total.pct"],
  "query": {
    "bool": {
      "must": [
        {"match": { "event.dataset": "system.process" }},
        {"range": { "@timestamp": { "gte": "now-30m" } } },
        {"match": { "process.name": "gnome-shell" } }
      ]
    }
  }, 
  "aggs": {
    "max_cpu": { "max": { "field": "system.process.cpu.total.pct" } }
  }
}

```

Returned a response like this:

```auto

{
  "took" : 896,
  "timed_out" : false,
  "_shards" : {
    "total" : 1,
    "successful" : 1,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 180,
      "relation" : "eq"
    },
    "max_score" : 4.0646133,
    "hits" : [
      {
        "_index" : "metricbeat-2022.11.17",
        "_id" : "GtKphoQBTwBiL9RwTxkO",
        "_score" : 4.0646133,
        "_source" : {
          "system" : {
            "process" : {
              "cpu" : {
                "total" : {
                  "pct" : 0.1149
                }
              }
            }
          }
        }
      },
      {
        "_index" : "metricbeat-2022.11.17",
        "_id" : "LNKphoQBTwBiL9RwWhnI",
        "_score" : 4.0646133,
        "_source" : {
          "system" : {
            "process" : {
              "cpu" : {
                "total" : {
                  "pct" : 0.1279
                }
              }
            }
          }
        }
      }
    ]
  },
  "aggregations" : {
    "max_cpu" : {
      "value" : 0.0
    }
  }
}

```

How is it possible that at least one returned document has a positive value for system.process.cpu.total.pct, but the max aggregation returns zero?

---

<div class="post-metadata">

**Author:** ![iamthealex1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iamthealex1/32/111669_2.png) [@iamthealex1](https://discuss.elastic.co/u/iamthealex1)\
**Post date:** [November 17, 2022, 6:16pm UTC](https://discuss.elastic.co/t/impossible-query-response/319236/2 "2022-11-17T18:16:10Z")

</div>

FWIW, the type of that field is long:

`GET metricbeat-2022.11.17/_mapping/field/system.process.cpu.total.pct`

```auto

{
  "metricbeat-2022.11.17" : {
    "mappings" : {
      "system.process.cpu.total.pct" : {
        "full_name" : "system.process.cpu.total.pct",
        "mapping" : {
          "pct" : {
            "type" : "long"
          }
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![iamthealex1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iamthealex1/32/111669_2.png) [@iamthealex1](https://discuss.elastic.co/u/iamthealex1)\
**Post date:** [November 17, 2022, 6:56pm UTC](https://discuss.elastic.co/t/impossible-query-response/319236/3 "2022-11-17T18:56:19Z")

</div>

I'm not sure why the mapping was "long". To me it seems it should've been double.

---

<div class="post-metadata">

**Author:** ![iamthealex1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iamthealex1/32/111669_2.png) [@iamthealex1](https://discuss.elastic.co/u/iamthealex1)\
**Post date:** [November 17, 2022, 7:50pm UTC](https://discuss.elastic.co/t/impossible-query-response/319236/4 "2022-11-17T19:50:35Z")

</div>

I was trying to have metricbeat write to a file and to have filebeat read the metricbeat files.  
With that approach, I missed loading the metricbeat mappings.  
I removed my data, ran metricbeat briefly with the elasticsearch output enbabled to install the mappings.  
After verifying that the correct mappings were in place in Elasticsearch, I replaced the metricbeat output to go to a file and started filebeat.

All looks good now.

_phew_

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 15, 2022, 7:50pm UTC](https://discuss.elastic.co/t/impossible-query-response/319236/5 "2022-12-15T19:50:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
