# Last Bucket displayed difference in Windows and Linux

**URL:** <https://discuss.elastic.co/t/last-bucket-displayed-difference-in-windows-and-linux/196193>\
**Category:** Kibana\
**Created:** [August 21, 2019, 9:17pm UTC](https://discuss.elastic.co/t/last-bucket-displayed-difference-in-windows-and-linux/196193 "2019-08-21T21:17:17Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mhare](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mhare/32/52213_2.png) [@mhare](https://discuss.elastic.co/u/mhare)\
**Post date:** [August 21, 2019, 9:17pm UTC](https://discuss.elastic.co/t/last-bucket-displayed-difference-in-windows-and-linux/196193/1 "2019-08-21T21:17:18Z")

</div>

Not a big deal, just an observation  
I have a 7.3 stack on a Windows laptop and another 7.3 stack on Ubuntu  
Both stacks are ingesting data from a common drive share, so it's the same data  
Both are basically configured the same (logstash filters, etc..)  
I design dashboards on the laptop and export them to Ubuntu for people to use.  
I am using a TSVB visualization and in the panel options I have "Drop last bucket" set to Yes

On Windows the last data point is take a full hour before the last hour, e.g at 16:30 the last data point is 15:00:00.000. On Ubuntu the same graph has the last data point at 16:00:00.000

Both are advertising 'per 60 min' on the graphs

Did I miss some configuration on one of the platforms that causes this, or do they just work slightly differently. Like I said, it's not a big deal, just on observation.

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [August 21, 2019, 10:55pm UTC](https://discuss.elastic.co/t/last-bucket-displayed-difference-in-windows-and-linux/196193/2 "2019-08-21T22:55:41Z")

</div>

The difference in results should be explainable by looking at the queries sent out by the visualizations. Many of the visualization have an `Inspect` feature that lets you see the search query that was generated and sent to Elasticsearch. For the buckets and partial filter dropping, it's not totally surprising that different client machines would show different.

- The way Elasticsearch groups metrics into time buckets depends heavily on the time filter that is in the query
- Differences in the client machines' clocks will for slight differences in the from/to times that potentially changes the set of buckets in the result
- Differences in the client machines' clocks can also mean that one client detects a result bucket as being partial data (the reason for wanting to drop the last bucket), while a different client might not have detected the bucket as being partial data.

Only if you can assume that both machines craft the same search query with the same time range filters, should Elasticsearch return the same results on the 2 machines.

---

<div class="post-metadata">

**Author:** ![mhare](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mhare/32/52213_2.png) [@mhare](https://discuss.elastic.co/u/mhare)\
**Post date:** [August 22, 2019, 1:47pm UTC](https://discuss.elastic.co/t/last-bucket-displayed-difference-in-windows-and-linux/196193/3 "2019-08-22T13:47:52Z")

</div>

Makes sense. Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 19, 2019, 1:47pm UTC](https://discuss.elastic.co/t/last-bucket-displayed-difference-in-windows-and-linux/196193/4 "2019-09-19T13:47:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
