# Kibana Term Aggregation

**URL:** <https://discuss.elastic.co/t/kibana-term-aggregation/234367>\
**Category:** Kibana\
**Created:** [May 26, 2020, 3:11pm UTC](https://discuss.elastic.co/t/kibana-term-aggregation/234367 "2020-05-26T15:11:00Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Fernando1](https://avatars.discourse-cdn.com/v4/letter/f/22d042/32.png) [@Fernando1](https://discuss.elastic.co/u/Fernando1)\
**Post date:** [May 26, 2020, 3:11pm UTC](https://discuss.elastic.co/t/kibana-term-aggregation/234367/1 "2020-05-26T15:11:00Z")

</div>

Hello!! How are you?

My kibana is having issues when doing aggregation visualizations.  
Here it is what is happening I have a SQL database as its source system, that has its data extracted by Logstash and feed the Elasticsearch index with the query (denormalized query joining 3 target tables).  
Everything goes ok, no data gets lost along the way (I've extracted the data from Elasticsearch and compared against the SQL data by counting rows and summing amount fields).  
However in Kibana when I do a metric count (like what I do in the Python Script and what I do in SQL SUM, or COUNT) the values don't match.

Can anyone help me please? This is bugging me for a long time now.

Beest Wishes,  
Fernando Durier.

My setup now:  
Elasticsearch running on IBM Openshift Cluster on IBM Cloud  
Logstash running on a pod inside IBM Openshift Cluster on IBM Cloud  
Kibana running on a pod inside IBM Openshift Cluster on IBM Cloud  
Source Database -\> DB2forZ/OS  
Index -\> replicas:1; number\_of\_rows:63290; shard:1;

P.s.: Even the counts on kibana don't match the number of docs in elasticsearch, e.g.: 63290 is the correct number of documents across my pipeline, and in Kibana it counts as 61,420.

---

<div class="post-metadata">

**Author:** ![Fernando1](https://avatars.discourse-cdn.com/v4/letter/f/22d042/32.png) [@Fernando1](https://discuss.elastic.co/u/Fernando1)\
**Post date:** [May 26, 2020, 3:34pm UTC](https://discuss.elastic.co/t/kibana-term-aggregation/234367/2 "2020-05-26T15:34:02Z")

</div>

I've rerun the count now, just for experimental purposes, and it changed again...

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/e/be5d82f526163b3b04e19aed07cad1f147346317.png)

---

<div class="post-metadata">

**Author:** ![Dzmitry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dzmitry/32/65026_2.png) [@Dzmitry](https://discuss.elastic.co/u/Dzmitry)\
**Post date:** [May 26, 2020, 5:21pm UTC](https://discuss.elastic.co/t/kibana-term-aggregation/234367/3 "2020-05-26T17:21:33Z")

</div>

Hi @Fernando1

You probably need to adjust time picker to include all the injected data:

 ![Visualize - Elastic 2020-05-26 19-16-08](https://us1.discourse-cdn.com/elastic/original/3X/4/4/4424473a820f58cf320406f7fcbfe5d70db376b0.jpeg)

You can cross-check for the documents count on Discover as well.

Just to confirm: to get number of documents you are using `GET _cat/indices/<your_index>` on DevTools page.

Regards, Dzmitry

---

<div class="post-metadata">

**Author:** ![Fernando1](https://avatars.discourse-cdn.com/v4/letter/f/22d042/32.png) [@Fernando1](https://discuss.elastic.co/u/Fernando1)\
**Post date:** [May 26, 2020, 5:47pm UTC](https://discuss.elastic.co/t/kibana-term-aggregation/234367/4 "2020-05-26T17:47:19Z")

</div>

> [@Dzmitry](#):
>
> GET \_cat/indices/\<your\_index\>

Hi, Dzmitry!!  
Thanks for answering.  
My time picker is set from 1980 till nowadays. (And my oldest registry would be from 2017).  
Still the count don't match.  
But the command you asked me to try the GET\_cat/indices/ worked and brought the expected value alright.

---

<div class="post-metadata">

**Author:** ![Fernando1](https://avatars.discourse-cdn.com/v4/letter/f/22d042/32.png) [@Fernando1](https://discuss.elastic.co/u/Fernando1)\
**Post date:** [May 26, 2020, 5:50pm UTC](https://discuss.elastic.co/t/kibana-term-aggregation/234367/5 "2020-05-26T17:50:58Z")

</div>

It seems to be the Kibana count aggregation function that is not working properly, or has a default config that I need to overwrite somehow.

---

<div class="post-metadata">

**Author:** ![Fernando1](https://avatars.discourse-cdn.com/v4/letter/f/22d042/32.png) [@Fernando1](https://discuss.elastic.co/u/Fernando1)\
**Post date:** [May 26, 2020, 7:13pm UTC](https://discuss.elastic.co/t/kibana-term-aggregation/234367/6 "2020-05-26T19:13:42Z")

</div>

Hey, Dzmitry in the end you are right!!  
In fact my data oldest registry is from 2017, however, my data has also future markers, that was missing!! hahahhaha  
Thanks again!!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 23, 2020, 7:13pm UTC](https://discuss.elastic.co/t/kibana-term-aggregation/234367/7 "2020-06-23T19:13:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
