# Miscalculation on aggregations?

**URL:** <https://discuss.elastic.co/t/miscalculation-on-aggregations/43004>\
**Category:** Elasticsearch\
**Created:** [February 29, 2016, 1:52pm UTC](https://discuss.elastic.co/t/miscalculation-on-aggregations/43004 "2016-02-29T13:52:06Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![cero-t](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cero-t/32/28149_2.png) [@cero-t](https://discuss.elastic.co/u/cero-t)\
**Post date:** [February 29, 2016, 1:52pm UTC](https://discuss.elastic.co/t/miscalculation-on-aggregations/43004/1 "2016-02-29T13:52:06Z")

</div>

Hello,  
I'm analyzing access logs with Elasticsearch 2.2 and Kibana 4.4.1. And I have trouble with calculation results of the filter aggregations.

For example, I created the "Data table" with following condition.

metrics

- Aggregation : Unique count
- Field : clientip

buckets

- Split Table
  - Filters
    - useragent.device: "iPhone"

- Split Row
  - Filters
    - 
      - 

(Actually I want to create filter of user agents and url paths)

I got "41,780" as the result count with my log collections.  
Then when I remove the second filter, Filters of Split Row, I got "56,386".

I have understood that "_" filter does nothing then the results should be same, but as a fact, they are different.  
It seems doubled filter aggregations cause some calculation error. Of course not only "_" filter, but also other condition seems to cause miscalculation.

Do I misunderstand something? Or is there any difficulties with doubled filter aggregation?

Here I copy my queries with/without second filter.

Without second filter.

> {  
> "query": {  
> "filtered": {  
> "query": {  
> "query\_string": {  
> "analyze\_wildcard": true,  
> "lowercase\_expanded\_terms": false,  
> "query": "\*"  
> }  
> },  
> "filter": {  
> "bool": {  
> "must": [  
> {  
> "range": {  
> "@timestamp": {  
> "gte": 1456106274723,  
> "lte": 1456711074723,  
> "format": "epoch\_millis"  
> }  
> }  
> }  
> ],  
> "must\_not":   
> }  
> }  
> }  
> },  
> "size": 0,  
> "aggs": {  
> "2": {  
> "filters": {  
> "filters": {  
> "iPhone": {  
> "query": {  
> "query\_string": {  
> "query": "useragent.device: "iPhone"",  
> "analyze\_wildcard": true,  
> "lowercase\_expanded\_terms": false  
> }  
> }  
> }  
> }  
> },  
> "aggs": {  
> "4": {  
> "cardinality": {  
> "field": "clientip"  
> }  
> }  
> }  
> }  
> }  
> }

With second filter.

> {  
> "query": {  
> "filtered": {  
> "query": {  
> "query\_string": {  
> "analyze\_wildcard": true,  
> "lowercase\_expanded\_terms": false,  
> "query": "_"  
> }  
> },  
> "filter": {  
> "bool": {  
> "must": [  
> {  
> "range": {  
> "@timestamp": {  
> "gte": 1456106274723,  
> "lte": 1456711074723,  
> "format": "epoch\_millis"  
> }  
> }  
> }  
> ],  
> "must\_not": []  
> }  
> }  
> }  
> },  
> "size": 0,  
> "aggs": {  
> "2": {  
> "filters": {  
> "filters": {  
> "iPhone": {  
> "query": {  
> "query\_string": {  
> "query": "useragent.device: "iPhone"",  
> "analyze\_wildcard": true,  
> "lowercase\_expanded\_terms": false  
> }  
> }  
> }  
> }  
> },  
> "aggs": {  
> "5": {  
> "filters": {  
> "filters": {  
> "_": {  
> "query": {  
> "query\_string": {  
> "query": "\*",  
> "analyze\_wildcard": true,  
> "lowercase\_expanded\_terms": false  
> }  
> }  
> }  
> }  
> },  
> "aggs": {  
> "4": {  
> "cardinality": {  
> "field": "clientip"  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }

Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:12pm UTC](https://discuss.elastic.co/t/miscalculation-on-aggregations/43004/2 "2017-07-05T23:12:51Z")

</div>


