# Kibana - strange behavior using search on long field

**URL:** <https://discuss.elastic.co/t/kibana-strange-behavior-using-search-on-long-field/284628>\
**Category:** Kibana\
**Created:** [September 20, 2021, 1:46pm UTC](https://discuss.elastic.co/t/kibana-strange-behavior-using-search-on-long-field/284628 "2021-09-20T13:46:02Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![JimJ](https://avatars.discourse-cdn.com/v4/letter/j/76d3ee/32.png) [@JimJ](https://discuss.elastic.co/u/JimJ)\
**Post date:** [September 20, 2021, 1:46pm UTC](https://discuss.elastic.co/t/kibana-strange-behavior-using-search-on-long-field/284628/1 "2021-09-20T13:46:02Z")

</div>

Hi,

I am using an Elastic+Logstash+kibana 7.12 stack.

And I get a very strange behavior.

I send log files using filebeat to logstash.  
Log files contain lines in json format.  
logstash parses them using the std json filter and send them to elastic.  
When I search in the kibana Discover tool, I got very strange things.

Searching on field named trace.requestID (number long) putting this in kibana KQL filter:  
trace.requestId : 20213800080838954

(this is the real value I can see in log files)

I get these documents:  
|Time|trace.requestId|  
|Sep 20, 2021 @ 14:49:15.000|20213800080838952|  
|Sep 20, 2021 @ 14:49:15.000|20213800080838952|  
|Sep 20, 2021 @ 14:49:15.000|20213800080838952|

And if I open them, I see same value in "Table" pane but in JSON, I get this:  
"trace.requestId": [  
20213800080838950  
],

I copied/pasted the kibana search from the inspect panel and re-did it in the Dev Tool, and there I am getting the right value. I guess it means the douments are okay in Elastic (which is reassuring in itself).

Any help welcome to explain what is happening.

Thank you in advance for your help.

---

<div class="post-metadata">

**Author:** ![JimJ](https://avatars.discourse-cdn.com/v4/letter/j/76d3ee/32.png) [@JimJ](https://discuss.elastic.co/u/JimJ)\
**Post date:** [September 20, 2021, 1:52pm UTC](https://discuss.elastic.co/t/kibana-strange-behavior-using-search-on-long-field/284628/2 "2021-09-20T13:52:34Z")

</div>

screenshots to demo the problem.

Searching in kibana:

 ![kibana-scopy01](https://us1.discourse-cdn.com/elastic/original/3X/b/8/b88609867c0a588f409a3193db2988d0fce9d62b.png)

Opening the document and switching to JSON:

 ![kibana-scopy02](https://us1.discourse-cdn.com/elastic/original/3X/2/7/277f0d7332a3715f7a04d9de4f6ce169a7207ccd.png)

---

<div class="post-metadata">

**Author:** ![Marco\_Liberati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marco_liberati/32/82953_2.png) [@Marco\_Liberati](https://discuss.elastic.co/u/Marco_Liberati)\
**Post date:** [September 20, 2021, 2:14pm UTC](https://discuss.elastic.co/t/kibana-strange-behavior-using-search-on-long-field/284628/3 "2021-09-20T14:14:28Z")

</div>

Hi @JimJ ,

Can you confirm that you see in the Inspect Statistics tab 3 `Hits`?  
Also, when executing the query in DevTools, if you change the `track_total_hits` value to `true`, do you get the `hits.total.value` of 1 or 3?

---

<div class="post-metadata">

**Author:** ![JimJ](https://avatars.discourse-cdn.com/v4/letter/j/76d3ee/32.png) [@JimJ](https://discuss.elastic.co/u/JimJ)\
**Post date:** [September 20, 2021, 2:27pm UTC](https://discuss.elastic.co/t/kibana-strange-behavior-using-search-on-long-field/284628/4 "2021-09-20T14:27:27Z")

</div>

hi Marco,

I see 3 in both Inspect Statistics tab Hits and in hits.total.value in DevTools.

---

<div class="post-metadata">

**Author:** ![Marco\_Liberati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marco_liberati/32/82953_2.png) [@Marco\_Liberati](https://discuss.elastic.co/u/Marco_Liberati)\
**Post date:** [September 20, 2021, 2:38pm UTC](https://discuss.elastic.co/t/kibana-strange-behavior-using-search-on-long-field/284628/5 "2021-09-20T14:38:30Z")

</div>

If you show the `_id` in Discover, can you see 3 distinct ids for the documents or the same one?

If there are 3 distinct `_id`s you have probably 3 documents with the same `trace.requestId` value stored.

---

<div class="post-metadata">

**Author:** ![JimJ](https://avatars.discourse-cdn.com/v4/letter/j/76d3ee/32.png) [@JimJ](https://discuss.elastic.co/u/JimJ)\
**Post date:** [September 21, 2021, 5:44am UTC](https://discuss.elastic.co/t/kibana-strange-behavior-using-search-on-long-field/284628/6 "2021-09-21T05:44:52Z")

</div>

hi @Marco_Liberati

Yes, I have 3 documents with trace.requestId : 20213800080838954.

My question is: why the Kibana Discover interface displays this values:

```auto
|Time|_id|trace.requestId|
|Sep 20, 2021 @ 14:49:15.000|U15BA3wBaAGIOcErCZjU|20213800080838952|
|Sep 20, 2021 @ 14:49:15.000|Ul5BA3wBaAGIOcErCZjT|20213800080838952|
|Sep 20, 2021 @ 14:49:15.000|VF5BA3wBaAGIOcErCZjV|20213800080838952|

```

And if I expand the documents and go to the JSON tab, I see this value:

```auto
"trace.requestId": [
      20213800080838950
    ],

```

So, data are okay in Elastic but Kibana Discover displays something completely wrong.

To summarize,  
real value is trace.requestId : 20213800080838954  
values displayed in Discover is trace.requestId : 20213800080838952  
values displayed in expanded Table tab is trace.requestId : 20213800080838952  
values displayed in expanded JSON tab is trace.requestId : 20213800080838950

---

<div class="post-metadata">

**Author:** ![JimJ](https://avatars.discourse-cdn.com/v4/letter/j/76d3ee/32.png) [@JimJ](https://discuss.elastic.co/u/JimJ)\
**Post date:** [September 21, 2021, 5:56am UTC](https://discuss.elastic.co/t/kibana-strange-behavior-using-search-on-long-field/284628/7 "2021-09-21T05:56:44Z")

</div>

Small additional info

I opened Kibana in Firefox, Chrome, Edge, same behavior.  
And nothing special in the browser's console.

And it is the same for almost all the documents: the values displayed in Discover do not correspond to the values in the real documents.

Do you thing it will help if I attached the 3 small documents I used as example to this discussion ?

---

<div class="post-metadata">

**Author:** ![Marco\_Liberati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marco_liberati/32/82953_2.png) [@Marco\_Liberati](https://discuss.elastic.co/u/Marco_Liberati)\
**Post date:** [September 21, 2021, 6:46am UTC](https://discuss.elastic.co/t/kibana-strange-behavior-using-search-on-long-field/284628/8 "2021-09-21T06:46:31Z")

</div>

Sorry, now I understand the real issue here.

In your screenshot you searched for ` ****4` but Discover is showing you something `**** 2` and opening the Table/JSON renderer it shows ` **** 0`.  
I didn't spot the last digit there as they differ.

This is a known issue with Discover and other Kibana apps. You can track the progress of the issue here: [https://github.com/elastic/kibana/issues/40183](https://github.com/elastic/kibana/issues/40183)

---

<div class="post-metadata">

**Author:** ![JimJ](https://avatars.discourse-cdn.com/v4/letter/j/76d3ee/32.png) [@JimJ](https://discuss.elastic.co/u/JimJ)\
**Post date:** [September 21, 2021, 6:53am UTC](https://discuss.elastic.co/t/kibana-strange-behavior-using-search-on-long-field/284628/9 "2021-09-21T06:53:44Z")

</div>

Thank's Marco.

So, immediate solution is to switch from a long int to a string if JS does not support 64bit int.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 19, 2021, 6:54am UTC](https://discuss.elastic.co/t/kibana-strange-behavior-using-search-on-long-field/284628/10 "2021-10-19T06:54:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
