# Mismatch between Elastic Query Aggretion and Kibana Visualize Function

**URL:** <https://discuss.elastic.co/t/mismatch-between-elastic-query-aggretion-and-kibana-visualize-function/333619>\
**Category:** Kibana\
**Created:** [May 17, 2023, 3:31am UTC](https://discuss.elastic.co/t/mismatch-between-elastic-query-aggretion-and-kibana-visualize-function/333619 "2023-05-17T03:31:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![phong\_elastic](https://avatars.discourse-cdn.com/v4/letter/p/ce73a5/32.png) [@phong\_elastic](https://discuss.elastic.co/u/phong_elastic)\
**Post date:** [May 17, 2023, 3:31am UTC](https://discuss.elastic.co/t/mismatch-between-elastic-query-aggretion-and-kibana-visualize-function/333619/1 "2023-05-17T03:31:04Z")

</div>

Hello everyone.  
I'm trying create a table that have the same data like the table in Lens Visualization by using the Elasticsearch Query.  
I'm confusing cause there's is a different between the data I get by the query and the data in the Visualization.  
Please help me!!  
Here's the code query I use to get the average data of system.cpu.user.pct in today:

```auto
GET metricbeat-*/_search
{
  "size": 0, 
  "query": {
    "bool": {
      "must": [
        {
          "exists": {
            "field": "system.cpu.user.pct"
          }
        },
        {
          "range": {
            "@timestamp": {
              "gte": "now/d",
              "lte": "now"
            }
          }
        }
      ]
    }
  },
  "aggs": {
    "avg_memory": {
      "avg": {
        "field": "system.cpu.user.pct"
      }
    }
  }
}

```

And here is the function in the table to get that data in Lens, notice that I set the same timerange as I used in the query:

 ![Screenshot from 2023-05-17 10-24-49](https://us1.discourse-cdn.com/elastic/original/3X/b/9/b98d2d3ccefac31b438facadb3c5e6fc0585f927.png)  
The result returns 0.852 meanwhile when I use Elastic Query it returns 0.9846911170688114  
That's a huge different between them.

---

<div class="post-metadata">

**Author:** ![phong\_elastic](https://avatars.discourse-cdn.com/v4/letter/p/ce73a5/32.png) [@phong\_elastic](https://discuss.elastic.co/u/phong_elastic)\
**Post date:** [May 17, 2023, 4:29am UTC](https://discuss.elastic.co/t/mismatch-between-elastic-query-aggretion-and-kibana-visualize-function/333619/2 "2023-05-17T04:29:42Z")

</div>

Sorry guys just my mistake.  
The range query must be

```auto
GET metricbeat-*/_search
{
  "size": 0, 
  "query": {
    "bool": {
      "must": [
        {
          "exists": {
            "field": "system.cpu.user.pct"
          }
        },
        {
          "range": {
            "@timestamp": {
              "gte": "now-7/d",
              "lte": "now"
            }
          }
        }
      ]
    }
  },
  "aggs": {
    "avg_memory": {
      "avg": {
        "field": "system.cpu.user.pct"
      }
    }
  }
}

```

Cause my time is UTC+7

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2023, 4:29am UTC](https://discuss.elastic.co/t/mismatch-between-elastic-query-aggretion-and-kibana-visualize-function/333619/3 "2023-06-14T04:29:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
