# "missing" agg weird results

**URL:** <https://discuss.elastic.co/t/missing-agg-weird-results/212430>\
**Category:** Elasticsearch\
**Created:** [December 19, 2019, 3:30am UTC](https://discuss.elastic.co/t/missing-agg-weird-results/212430 "2019-12-19T03:30:38Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![dvisz-inf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dvisz-inf/32/42617_2.png) [@dvisz-inf](https://discuss.elastic.co/u/dvisz-inf)\
**Post date:** [December 19, 2019, 3:30am UTC](https://discuss.elastic.co/t/missing-agg-weird-results/212430/1 "2019-12-19T03:30:38Z")

</div>

I get some odd looking results from this query:

```auto
POST my-index/_search?pretty
{
  "size": 0,
  "aggs": {
    "a": {
      "terms": {
        "field": "foo.a"
      },
      "aggs": {
        "missing_b": {
          "missing": {
            "field": "foo.b"
          }
        },
        "having_b": {
          "filter": {
            "exists": {
              "field": "foo.b"
            }
          }
        }
      }
    }
  }
}

```

I would have thought that the `missing_b` and `having_b` aggregation instances  
would have been complementary, but these are the results that I get:

```auto
{
  "took" : 25,
  "timed_out" : false,
  "_shards" : {
    "total" : 10,
    "successful" : 10,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : 330621654,
    "max_score" : 0.0,
    "hits" : []
  },
  "aggregations" : {
    "a" : {
      "doc_count_error_upper_bound" : 0,
      "sum_other_doc_count" : 0,
      "buckets" : [
        {
          "key" : "a2",
          "doc_count" : 327720,
          "having_b" : {
            "doc_count" : 136435
          },
          "missing_b" : {
            "doc_count" : 327720
          }
        },
        {
          "key" : "a1",
          "doc_count" : 102243,
          "having_b" : {
            "doc_count" : 52350
          },
          "missing_b" : {
            "doc_count" : 102243
          }
        },
        {
          "key" : "a0",
          "doc_count" : 13839,
          "having_b" : {
            "doc_count" : 0
          },
          "missing_b" : {
            "doc_count" : 13839
          }
        },
        {
          "key" : "a3",
          "doc_count" : 8108,
          "having_b" : {
            "doc_count" : 2787
          },
          "missing_b" : {
            "doc_count" : 8108
          }
        },
        {
          "key" : "a4",
          "doc_count" : 787,
          "having_b" : {
            "doc_count" : 0
          },
          "missing_b" : {
            "doc_count" : 787
          }
        }
      ]
    }
  }
}

```

Implementing `missing` agg myself using `filter` agg:

```auto
POST my-index/_search?pretty
{
  "size": 0,
  "aggs": {
    "a": {
      "terms": {
        "field": "foo.a"
      },
      "aggs": {
        "missing_b": {
          "filter": {
            "bool": {
              "must_not": {
                "exists": {
                  "field": "foo.b"
                }
              }
            }
          }
        },
        "having_b": {
          "filter": {
            "exists": {
              "field": "foo.b"
            }
          }
        }
      }
    }
  }
}

```

Seems to give me the expected result:

```auto
{
  "took" : 67590,
  "timed_out" : false,
  "_shards" : {
    "total" : 10,
    "successful" : 10,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : 330621654,
    "max_score" : 0.0,
    "hits" : []
  },
  "aggregations" : {
    "a" : {
      "doc_count_error_upper_bound" : 0,
      "sum_other_doc_count" : 0,
      "buckets" : [
        {
          "key" : "a2",
          "doc_count" : 327720,
          "having_b" : {
            "doc_count" : 136435
          },
          "missing_b" : {
            "doc_count" : 191285
          }
        },
        {
          "key" : "a1",
          "doc_count" : 102243,
          "having_b" : {
            "doc_count" : 52350
          },
          "missing_b" : {
            "doc_count" : 49893
          }
        },
        {
          "key" : "a0",
          "doc_count" : 13839,
          "having_b" : {
            "doc_count" : 0
          },
          "missing_b" : {
            "doc_count" : 13839
          }
        },
        {
          "key" : "a3",
          "doc_count" : 8108,
          "having_b" : {
            "doc_count" : 2787
          },
          "missing_b" : {
            "doc_count" : 5321
          }
        },
        {
          "key" : "a4",
          "doc_count" : 787,
          "having_b" : {
            "doc_count" : 0
          },
          "missing_b" : {
            "doc_count" : 787
          }
        }
      ]
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![dvisz-inf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dvisz-inf/32/42617_2.png) [@dvisz-inf](https://discuss.elastic.co/u/dvisz-inf)\
**Post date:** [January 8, 2020, 9:46pm UTC](https://discuss.elastic.co/t/missing-agg-weird-results/212430/2 "2020-01-08T21:46:47Z")

</div>

Should this be reported as a bug instead?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 5, 2020, 9:46pm UTC](https://discuss.elastic.co/t/missing-agg-weird-results/212430/3 "2020-02-05T21:46:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
