# Kibana Query Displaying Incorrect Results

**URL:** <https://discuss.elastic.co/t/kibana-query-displaying-incorrect-results/228703>\
**Category:** Kibana\
**Created:** [April 19, 2020, 6:58am UTC](https://discuss.elastic.co/t/kibana-query-displaying-incorrect-results/228703 "2020-04-19T06:58:58Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![vikramaddagulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikramaddagulla/32/139858_2.png) [@vikramaddagulla](https://discuss.elastic.co/u/vikramaddagulla)\
**Post date:** [April 19, 2020, 6:58am UTC](https://discuss.elastic.co/t/kibana-query-displaying-incorrect-results/228703/1 "2020-04-19T06:58:58Z")

</div>

Hi,

I am trying to view the logs which have higher time-taken parameter.

In many of the logs, I can see that the time taken parameter is logged in as 8.000, 15.500, 15.753 etc

If I try to search with timetaken \> 8.000

Ideally, it should have displayed all results more than 8 but instead it displays only one result as shown below.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/1/31ff2292f1778b1c3c71da87bb264e227916d4c9.png)

I had changed my query as below and then I can see the results. Any suggestion what is going wrong ?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/0/00061eb1410df8d5b739cb6fb33efdfec819a759.png)

Ideally the result set for timetaken \> 8.000 and timetaken \> 10.000 should have been identical.

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [April 20, 2020, 8:17am UTC](https://discuss.elastic.co/t/kibana-query-displaying-incorrect-results/228703/2 "2020-04-20T08:17:16Z")

</div>

Hi

Are you sure that timetaken is a numeric data type? It looks like it's a textual type which could explain this behavior.

Best,  
Matthias

---

<div class="post-metadata">

**Author:** ![vikramaddagulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikramaddagulla/32/139858_2.png) [@vikramaddagulla](https://discuss.elastic.co/u/vikramaddagulla)\
**Post date:** [April 22, 2020, 4:42pm UTC](https://discuss.elastic.co/t/kibana-query-displaying-incorrect-results/228703/3 "2020-04-22T16:42:02Z")

</div>

i have changed the grok patter to match timetaken as below :

%{NUMBER:timetaken:float}

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/7/876b5e249208b559d04fce081abd10ad897aa698.png)

Any further suggestions ???

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [April 23, 2020, 5:25am UTC](https://discuss.elastic.co/t/kibana-query-displaying-incorrect-results/228703/4 "2020-04-23T05:25:20Z")

</div>

Yes, could you please post a screenshot that contains timetaken in the field list on the left , I'm interested which icon is displayed.  
thx!

---

<div class="post-metadata">

**Author:** ![vikramaddagulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikramaddagulla/32/139858_2.png) [@vikramaddagulla](https://discuss.elastic.co/u/vikramaddagulla)\
**Post date:** [April 23, 2020, 5:50am UTC](https://discuss.elastic.co/t/kibana-query-displaying-incorrect-results/228703/5 "2020-04-23T05:50:19Z")

</div>

> [@vikramaddagulla](#):
>
> timetaken as

Hope this is what you are looking for...

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/3/c33c969dd66780b7e49e19e0164faa0ee83fbfb6.png)

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [April 24, 2020, 7:47am UTC](https://discuss.elastic.co/t/kibana-query-displaying-incorrect-results/228703/6 "2020-04-24T07:47:11Z")

</div>

Thank, this looks like this isn't a numeric field, it's a text field, and that's why it doesn't work.

Could you export the mapping of an index that contains this field? You can do this in our Dev Tools Console application  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-mapping.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-mapping.html)

Of interest would be the mapping of timetaken

Also you could have a look management's index pattern, where you can configure the formatting of the fields.

Best,  
Matthias

---

<div class="post-metadata">

**Author:** ![vikramaddagulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikramaddagulla/32/139858_2.png) [@vikramaddagulla](https://discuss.elastic.co/u/vikramaddagulla)\
**Post date:** [April 24, 2020, 7:54am UTC](https://discuss.elastic.co/t/kibana-query-displaying-incorrect-results/228703/7 "2020-04-24T07:54:58Z")

</div>

Hello

Yes. It indeed looks like text field.

I have checked this from the Index Management screen --\> IndexName and checked the below in the mapping :

"timetaken": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256

Probably when the index was created first, it would have taken up the text type.

--\> I have now modified the logstash grok as below :  
%{NUMBER:timetaken:float}  
Does it not change the type now ?

--\> I have checked the format field in the index pattern and I cannot see option of changing it back to int or float.

---

<div class="post-metadata">

**Author:** ![lusynda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lusynda/32/53557_2.png) [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Post date:** [April 24, 2020, 8:16am UTC](https://discuss.elastic.co/t/kibana-query-displaying-incorrect-results/228703/8 "2020-04-24T08:16:29Z")

</div>

Well you need to change mapping of the index and not the grok in logstash.  
To do that you need to create an index template and set the mapping of that type to numeric and with integer or float, then reindex your old index to a new one to get the data to the new datatype

---

<div class="post-metadata">

**Author:** ![vikramaddagulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikramaddagulla/32/139858_2.png) [@vikramaddagulla](https://discuss.elastic.co/u/vikramaddagulla)\
**Post date:** [April 24, 2020, 4:18pm UTC](https://discuss.elastic.co/t/kibana-query-displaying-incorrect-results/228703/9 "2020-04-24T16:18:10Z")

</div>

Thank you...

reindex your old index to a new one ====\> Does it mean we cannot change the type in the existing index ?

Can we not re-index the data instead of creating new index ?

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [May 14, 2020, 5:52am UTC](https://discuss.elastic.co/t/kibana-query-displaying-incorrect-results/228703/10 "2020-05-14T05:52:38Z")

</div>

You cannot change the type in an existing index, you need to reindex it, and that means creating a new index

[https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html)

Best,  
Matthias

---

<div class="post-metadata">

**Author:** ![vikramaddagulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikramaddagulla/32/139858_2.png) [@vikramaddagulla](https://discuss.elastic.co/u/vikramaddagulla)\
**Post date:** [May 14, 2020, 6:09am UTC](https://discuss.elastic.co/t/kibana-query-displaying-incorrect-results/228703/11 "2020-05-14T06:09:24Z")

</div>

Thank you.

This topic can be closed.

I deleted and re-created the index. At the time of initial creation, i passed the data type in the grok pattern like below :

%{NUMBER:timetaken:float}

Then it started picking up the data in the new format.

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [May 14, 2020, 9:13am UTC](https://discuss.elastic.co/t/kibana-query-displaying-incorrect-results/228703/12 "2020-05-14T09:13:39Z")

</div>


