# Kibana Metric Aggregations showing different values

**URL:** <https://discuss.elastic.co/t/kibana-metric-aggregations-showing-different-values/126705>\
**Category:** Kibana\
**Created:** [April 4, 2018, 9:35am UTC](https://discuss.elastic.co/t/kibana-metric-aggregations-showing-different-values/126705 "2018-04-04T09:35:43Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![falsekingpin](https://avatars.discourse-cdn.com/v4/letter/f/aca169/32.png) [@falsekingpin](https://discuss.elastic.co/u/falsekingpin)\
**Post date:** [April 4, 2018, 9:35am UTC](https://discuss.elastic.co/t/kibana-metric-aggregations-showing-different-values/126705/1 "2018-04-04T09:35:43Z")

</div>

Hi ,  
I am applying min metric aggregation to a numeric field which has unix time, it is showing different value as it should show with the data. I have also tried querying elasticsearch  
Here is the response query:

curl -XGET 'ip:9200/filebeat-\*/\_search?pretty' -H 'Content-Type: application/json' -d'  
{  
"size": 0,  
"aggs": {  
"group\_by\_service-status": {  
"terms": {  
"field": "service-status.keyword"  
},  
"aggs": {  
"min\_unixTime": {  
"min": {  
"field": "unixTime"  
}  
}  
}  
}  
}  
}  
'

Here is the response:

{  
"took" : 38,  
"timed\_out" : false,  
"\_shards" : {  
"total" : 15,  
"successful" : 15,  
"skipped" : 0,  
"failed" : 0  
},  
"hits" : {  
"total" : 7781,  
"max\_score" : 0.0,  
"hits" :   
},  
"aggregations" : {  
"group\_by\_service-status" : {  
"doc\_count\_error\_upper\_bound" : 0,  
"sum\_other\_doc\_count" : 0,  
"buckets" : [  
{  
"key" : "DIFF",  
"doc\_count" : 1246,  
"min\_unixTime" : {  
"value" : 1.0013580322265625E-4  
}  
},  
{  
"key" : "START",  
"doc\_count" : 1142,  
"min\_unixTime" : {  
"value" : 1.522755712E9  
}  
},  
{  
"key" : "END",  
"doc\_count" : 936,  
"min\_unixTime" : {  
"value" : 1.522755712E9  
}  
}  
]  
}  
}  
}

I have attached my Kibana console, where it shows what the min value should be.

 ![Kibana-issue](https://us1.discourse-cdn.com/elastic/original/3X/7/2/7273c8ee1f21e52e56c39d7158ea3f701486be9d.png)

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [April 4, 2018, 3:36pm UTC](https://discuss.elastic.co/t/kibana-metric-aggregations-showing-different-values/126705/2 "2018-04-04T15:36:07Z")

</div>

I don't exactly get what value you would expect. It sounds like the Kibana one is the "correct" one, but ES returns wrong data but I highly doubt that. Can you do a `metrics aggregation` with the same Terms aggregation split (on the `service-status.keyword` field) and use the same min aggregation and show the output of that? I don't see where this table that you posted is actually coming from.

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![falsekingpin](https://avatars.discourse-cdn.com/v4/letter/f/aca169/32.png) [@falsekingpin](https://discuss.elastic.co/u/falsekingpin)\
**Post date:** [April 5, 2018, 11:23am UTC](https://discuss.elastic.co/t/kibana-metric-aggregations-showing-different-values/126705/3 "2018-04-05T11:23:24Z")

</div>

Hi,

Thanks for responding. Here is the aggregation applied in Kibana.  
 ![kibana-error](https://us1.discourse-cdn.com/elastic/original/3X/9/2/925650c37feee25f6f3c52cb98ff734949496084.png)

The value is 1,522,755,712 whereas the value I am expecting is 1,522,755,689 as shown in the screenshot in the previous post above.

And also as you can see from the query to Elasticsearch, the value for START is 1,522,755,712 which is same in the kibana aggregation but that is wrong.  
"key" : "START",  
"doc\_count" : 1142,  
"min\_unixTime" : {  
"value" : 1.522755712E9

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [April 9, 2018, 6:43pm UTC](https://discuss.elastic.co/t/kibana-metric-aggregations-showing-different-values/126705/4 "2018-04-09T18:43:59Z")

</div>

@timroes - can you please help here with this Aggregation question?

Many thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![falsekingpin](https://avatars.discourse-cdn.com/v4/letter/f/aca169/32.png) [@falsekingpin](https://discuss.elastic.co/u/falsekingpin)\
**Post date:** [April 11, 2018, 10:16am UTC](https://discuss.elastic.co/t/kibana-metric-aggregations-showing-different-values/126705/5 "2018-04-11T10:16:13Z")

</div>

Hi Rashmi, a little update, the aggregation is returning some value that does not exist.  
Like in the above kibana screenshot where the value is 1,522,755,712, theres no such value in any of the documents in the index. Also I confirmed the same with a smaller data set where while getting metric aggregation returned value which did not exist.

One more issue is that I am not getting correct metric aggregations on unix timestamp values(which i have indexed as float) , but when trying with smaller values like 1000, I am able to get correct metric aggreagtion. I tried with different supported data type i.e int,float,long for unix timestamp but still i am not getting correct output for metric aggregation.

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [April 12, 2018, 7:52am UTC](https://discuss.elastic.co/t/kibana-metric-aggregations-showing-different-values/126705/6 "2018-04-12T07:52:15Z")

</div>

Hi Askhay,

the actual issue could be in the datatype here. You should rather index your timestamp as `long` or `integer` values. The way floats (and in general IEEE 754 floating point values used in computers) work, they only store a specific precision. You numbers (or in general timestamp) seem to be large enough to be cut of in the end due to not enough precision.

That would also explain the mismatch you are seeing. Aggregations work on the indexed data, so you get whatever value is indexed (and maybe lost some precision there), whereas Discover (or the `_source` of any document, returned by a regular search), will show you the original values, that was stored - not the indexed ones. So you would still have the correct values in Discover, but lost some precision due to floating points in the indexed values (and thus aggregations). Btw, that mismatch would also affect search queries, so e.g. range queries on that field would behave the same weird way.

Could you please reindex your data using `long` instead of `float`. In general you should never use any floating point, if you know that you won't have decimal values, because you can always run in that precision issue (and in coding in general in some nasty rounding issues, etc.) 🙂

That would also explain why you get correct result with smaller numbers. Since you said you already tried indexing with `long` are you sure that index process went correctly? Could you paste the mappings for that index with `long` and also the request/responses, for an aggregation?

Cheers,  
Tim

---

<div class="post-metadata">

**Author:** ![falsekingpin](https://avatars.discourse-cdn.com/v4/letter/f/aca169/32.png) [@falsekingpin](https://discuss.elastic.co/u/falsekingpin)\
**Post date:** [April 12, 2018, 1:24pm UTC](https://discuss.elastic.co/t/kibana-metric-aggregations-showing-different-values/126705/7 "2018-04-12T13:24:44Z")

</div>

Hi Tim,  
I reindexed the data with integer type and the issue was solved.  
Could you please help me with this question?

> [@Create visualizations out of results of different visualization](https://discuss.elastic.co/t/create-visualizations-out-of-results-of-different-visualization/127746):
>
> Hi, I would like to know if we can create visualizations out of results of different visualization. Example: I have created two visualizations as follows This is min of a value based with aggregation: This is max of the same aggregation I would want to subtract the results of visualization like : max - min with the aggregation applied as same in max and min and then visualize the result. Is it possible in Kibana? And how could I do it?

Thanks  
Akshay

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [April 12, 2018, 2:42pm UTC](https://discuss.elastic.co/t/kibana-metric-aggregations-showing-different-values/126705/8 "2018-04-12T14:42:30Z")

</div>

Glad it solved your issue. Sorry btw for the typo I made in your name in my last response ☹

I will give your other question a look.

Cheers,  
Tim

---

<div class="post-metadata">

**Author:** ![falsekingpin](https://avatars.discourse-cdn.com/v4/letter/f/aca169/32.png) [@falsekingpin](https://discuss.elastic.co/u/falsekingpin)\
**Post date:** [April 13, 2018, 4:39am UTC](https://discuss.elastic.co/t/kibana-metric-aggregations-showing-different-values/126705/9 "2018-04-13T04:39:44Z")

</div>

Hey Tim,

Thanks for the solution!

Thanks,  
Akshay

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2018, 4:39am UTC](https://discuss.elastic.co/t/kibana-metric-aggregations-showing-different-values/126705/10 "2018-05-11T04:39:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
