# Kibana aggregation sum wrong result

**URL:** <https://discuss.elastic.co/t/kibana-aggregation-sum-wrong-result/199494>\
**Category:** Kibana\
**Created:** [September 14, 2019, 5:46am UTC](https://discuss.elastic.co/t/kibana-aggregation-sum-wrong-result/199494 "2019-09-14T05:46:44Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![111210](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/111210/32/54192_2.png) [@111210](https://discuss.elastic.co/u/111210)\
**Post date:** [September 14, 2019, 5:46am UTC](https://discuss.elastic.co/t/kibana-aggregation-sum-wrong-result/199494/1 "2019-09-14T05:46:45Z")

</div>

I don't understand why does Kibana sum different result when I just enable filter or disable filter.  
It should be same.

Disable

 ![01](https://us1.discourse-cdn.com/elastic/original/3X/0/4/04693b4bbc1b55a8ef54eda514bbb4b3bcdb06d8.png)

Enable

 ![02](https://us1.discourse-cdn.com/elastic/original/3X/0/8/08bbec5cf4757be7554602af1505274f018b580e.png)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 14, 2019, 9:23am UTC](https://discuss.elastic.co/t/kibana-aggregation-sum-wrong-result/199494/2 "2019-09-14T09:23:59Z")

</div>

When you aggregate across a number of agents each shard returns the top results. If the agent field is high cardinality and you have a number of shards it is possible that the sum for the specific agent does not make it into the top results from that shard. When you filter on a single agent this is no longer the case and the count is accurate.

If you look in the docs it is highlighted that some types of aggregations are approximate. This is done in order to ensure performance and limit resource usage when querying large data volumes.

---

<div class="post-metadata">

**Author:** ![111210](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/111210/32/54192_2.png) [@111210](https://discuss.elastic.co/u/111210)\
**Post date:** [September 15, 2019, 4:26am UTC](https://discuss.elastic.co/t/kibana-aggregation-sum-wrong-result/199494/3 "2019-09-15T04:26:03Z")

</div>

Thank you.

Is there any way to adjust this situation?  
Performance and resource is not a big issue for me. I can wait for longer seconds or minutes.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 15, 2019, 6:16am UTC](https://discuss.elastic.co/t/kibana-aggregation-sum-wrong-result/199494/4 "2019-09-15T06:16:26Z")

</div>

What is the cardinality of that field?

---

<div class="post-metadata">

**Author:** ![111210](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/111210/32/54192_2.png) [@111210](https://discuss.elastic.co/u/111210)\
**Post date:** [September 15, 2019, 7:05am UTC](https://discuss.elastic.co/t/kibana-aggregation-sum-wrong-result/199494/5 "2019-09-15T07:05:17Z")

</div>

It's just numbers.

 ![01](https://us1.discourse-cdn.com/elastic/original/3X/d/6/d6a7fe02b5dbd46a070682a7ecc8f1f86004cce6.png)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 15, 2019, 8:11am UTC](https://discuss.elastic.co/t/kibana-aggregation-sum-wrong-result/199494/6 "2019-09-15T08:11:20Z")

</div>

That is the type. Cardinality is how many different values the field contains.

---

<div class="post-metadata">

**Author:** ![111210](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/111210/32/54192_2.png) [@111210](https://discuss.elastic.co/u/111210)\
**Post date:** [September 15, 2019, 8:18am UTC](https://discuss.elastic.co/t/kibana-aggregation-sum-wrong-result/199494/7 "2019-09-15T08:18:18Z")

</div>

"agent\_name" have 1040 different values.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 15, 2019, 8:22am UTC](https://discuss.elastic.co/t/kibana-aggregation-sum-wrong-result/199494/8 "2019-09-15T08:22:47Z")

</div>

You can increase accuracy by increasing the size [as described in the docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#search-aggregations-bucket-terms-aggregation-size). I would recommend reading this as it described the problem and solutions quite well. Fewer large shards can also help reduce the error.

How much data do you have? How many indices and shards is this spread across?

---

<div class="post-metadata">

**Author:** ![111210](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/111210/32/54192_2.png) [@111210](https://discuss.elastic.co/u/111210)\
**Post date:** [September 16, 2019, 3:03am UTC](https://discuss.elastic.co/t/kibana-aggregation-sum-wrong-result/199494/9 "2019-09-16T03:03:08Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/0/a/0a643b0cd6b94a4f647900888757db69deeea47c.png)

![image](https://us1.discourse-cdn.com/elastic/original/3X/e/f/eff89d8c7c8a9e2dcab0d9785969f0da401979db.png)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 16, 2019, 5:25am UTC](https://discuss.elastic.co/t/kibana-aggregation-sum-wrong-result/199494/10 "2019-09-16T05:25:16Z")

</div>

Another way to get exact results is to have a single shard. At the size you are showing it may be an option but it may not scale and pperform less well.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 14, 2019, 5:25am UTC](https://discuss.elastic.co/t/kibana-aggregation-sum-wrong-result/199494/11 "2019-10-14T05:25:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
