# Kibana data table issue: Total greater than sum of individual parts

**URL:** <https://discuss.elastic.co/t/kibana-data-table-issue-total-greater-than-sum-of-individual-parts/116879>\
**Category:** Kibana\
**Created:** [January 24, 2018, 2:53pm UTC](https://discuss.elastic.co/t/kibana-data-table-issue-total-greater-than-sum-of-individual-parts/116879 "2018-01-24T14:53:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![geoff\_yalo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/geoff_yalo/32/28323_2.png) [@geoff\_yalo](https://discuss.elastic.co/u/geoff_yalo)\
**Post date:** [January 24, 2018, 2:53pm UTC](https://discuss.elastic.co/t/kibana-data-table-issue-total-greater-than-sum-of-individual-parts/116879/1 "2018-01-24T14:53:23Z")

</div>

Hi,

I'm using a Kibana data table and noticed something curious. When I apply my first keyword filter, I obtain the following count (I am using cumulative sum of unique count):

![image](https://us1.discourse-cdn.com/elastic/original/3X/0/5/05b9d77a1fffde033bf68315c0f29d7ff57e044b.png)

When I apply the 2nd filter separately, I obtain the following:

![image](https://us1.discourse-cdn.com/elastic/original/3X/3/1/319be06af6f5f0a5bb07a375103e668ce8b8f8cf.png)

However, when I use both keywords in a filter (as an OR statement), I get the following which you'll notice is greater than the sum of the 2 figures above:

![image](https://us1.discourse-cdn.com/elastic/original/3X/8/0/80b5e8a81f6787e0eac277161acc14ff23b8b2f6.png)

Anyone have an idea of what might be causing this? I'd understand if the combined figure were less than the sum of the two components, but that is not the case.

Thanks,  
Geoffrey

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [January 24, 2018, 5:35pm UTC](https://discuss.elastic.co/t/kibana-data-table-issue-total-greater-than-sum-of-individual-parts/116879/2 "2018-01-24T17:35:12Z")

</div>

The values provided by the [cardinality aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-metrics-cardinality-aggregation.html#_counts_are_approximate) are approximate counts. Set [precision control](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-metrics-cardinality-aggregation.html#_precision_control) for better accuracy.

---

<div class="post-metadata">

**Author:** ![geoff\_yalo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/geoff_yalo/32/28323_2.png) [@geoff\_yalo](https://discuss.elastic.co/u/geoff_yalo)\
**Post date:** [January 26, 2018, 6:41pm UTC](https://discuss.elastic.co/t/kibana-data-table-issue-total-greater-than-sum-of-individual-parts/116879/3 "2018-01-26T18:41:28Z")

</div>

Thanks @Nathan_Reese

it looks like the precision\_control threshold still does not allow for exact counts above the max threshold (40,000). Do you know if setting the "size" threshold to 0 works with cardinality aggregation?

Based on this [thread](https://discuss.elastic.co/t/option-for-exact-aggregation-instead-of-approximation/44996) it seems like that's an option for getting an exact count, but I can't seem to get it to work with the cardinality aggregation I'm using.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 23, 2018, 6:41pm UTC](https://discuss.elastic.co/t/kibana-data-table-issue-total-greater-than-sum-of-individual-parts/116879/4 "2018-02-23T18:41:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
