# Monitoring data not same with curl count why?

**URL:** <https://discuss.elastic.co/t/monitoring-data-not-same-with-curl-count-why/112532>\
**Category:** Elasticsearch\
**Created:** [December 20, 2017, 12:53am UTC](https://discuss.elastic.co/t/monitoring-data-not-same-with-curl-count-why/112532 "2017-12-20T00:53:14Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Post date:** [December 20, 2017, 12:53am UTC](https://discuss.elastic.co/t/monitoring-data-not-same-with-curl-count-why/112532/1 "2017-12-20T00:53:14Z")

</div>

```
[root@xx.xx.xx config]# curl -XGET http://xx.xx.xx:9200/xx-20171212-1224/_count?pretty
{
  "count" : **467110397** ,
  "_shards" : {
    "total" : 36,
    "successful" : 36,
    "skipped" : 0,
    "failed" : 0

```

**use kibana data count the data same with curl..**

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/5/850c252c564916bd12ef30fd783f51b81b0979db.png)  
**monitoring data not same with this..**  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/5/456263357a23060b9952f9fc97796cb9b8a43d34.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/d/6d7ec141db09bfebf05be35b57833601de763258.png)

---

<div class="post-metadata">

**Author:** ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Post date:** [December 21, 2017, 1:08am UTC](https://discuss.elastic.co/t/monitoring-data-not-same-with-curl-count-why/112532/2 "2017-12-21T01:08:20Z")

</div>

if i close the index. and open again.  
the output is bad..

"\_shards" : {  
"total" : 108,  
"successful" : 108,  
"failed" : 0  
},  
"\_all" : {  
"primaries" : {  
"docs" : {  
**"count" : 1164334263,**  
"deleted" : 0  
},  
"store" : {  
"size\_in\_bytes" : 175744377852,  
"throttle\_time\_in\_millis" : 0  
},  
"indexing" : {  
**"index\_total" : 0,**  
"index\_time\_in\_millis" : 0,  
"index\_current" : 0,  
"index\_failed" : 0,  
"delete\_total" : 0,  
"delete\_time\_in\_millis" : 0,  
"delete\_current" : 0,  
"noop\_update\_total" : 0,  
"is\_throttled" : false,  
"throttle\_time\_in\_millis" : 0  
},

why?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 21, 2017, 6:12am UTC](https://discuss.elastic.co/t/monitoring-data-not-same-with-curl-count-why/112532/3 "2017-12-21T06:12:52Z")

</div>

It looks ok to me.

---

<div class="post-metadata">

**Author:** ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Post date:** [December 21, 2017, 6:57am UTC](https://discuss.elastic.co/t/monitoring-data-not-same-with-curl-count-why/112532/4 "2017-12-21T06:57:23Z")

</div>

yes i see some indices in my cluster is the same .  
but one type of index is no same...

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 21, 2017, 9:49am UTC](https://discuss.elastic.co/t/monitoring-data-not-same-with-curl-count-why/112532/5 "2017-12-21T09:49:18Z")

</div>

In one case you count all the documents what ever the index is (`1.164.334.263`) and in the other case you just looked at one index named `xx-20171212-1224` (`467.110.397`).

So everything looks good to me.

---

<div class="post-metadata">

**Author:** ![sandeepkanabar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeepkanabar/32/79399_2.png) [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)\
**Post date:** [December 27, 2017, 4:17am UTC](https://discuss.elastic.co/t/monitoring-data-not-same-with-curl-count-why/112532/6 "2017-12-27T04:17:57Z")

</div>

But in one of the screenshots, it shows 1.2B documents for 1 index alone. It shows "1 of 177" indices.

---

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [December 27, 2017, 5:12am UTC](https://discuss.elastic.co/t/monitoring-data-not-same-with-curl-count-why/112532/7 "2017-12-27T05:12:32Z")

</div>

On the second screenshot, the count you see includes the nested documents that are present in top-level documents in your index.

---

<div class="post-metadata">

**Author:** ![sandeepkanabar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeepkanabar/32/79399_2.png) [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)\
**Post date:** [December 27, 2017, 5:15am UTC](https://discuss.elastic.co/t/monitoring-data-not-same-with-curl-count-why/112532/8 "2017-12-27T05:15:19Z")

</div>

Thanks for the clarification @val. Does that mean the `curl` request doesn't include the nested documents?

---

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [December 27, 2017, 5:19am UTC](https://discuss.elastic.co/t/monitoring-data-not-same-with-curl-count-why/112532/9 "2017-12-27T05:19:48Z")

</div>

The `_count` API does not include the number of nested documents in your index, indeed. Instead you can use the following call to get the correct doc count including the nested ones

`curl -XGET http://xx.xx.xx:9200/xx-20171212-1224/_stats/docs?pretty`

---

<div class="post-metadata">

**Author:** ![sandeepkanabar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeepkanabar/32/79399_2.png) [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)\
**Post date:** [December 27, 2017, 5:21am UTC](https://discuss.elastic.co/t/monitoring-data-not-same-with-curl-count-why/112532/10 "2017-12-27T05:21:49Z")

</div>

Awesome. It was quite a learning. Thank you Val.

---

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [December 27, 2017, 5:23am UTC](https://discuss.elastic.co/t/monitoring-data-not-same-with-curl-count-why/112532/11 "2017-12-27T05:23:08Z")

</div>

Always glad to help 😉

---

<div class="post-metadata">

**Author:** ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Post date:** [December 28, 2017, 2:54am UTC](https://discuss.elastic.co/t/monitoring-data-not-same-with-curl-count-why/112532/12 "2017-12-28T02:54:26Z")

</div>

> [@val](#):
>
> The \_count API does not include the number of nested documents in your index, indeed. Instead you can use the following call to get the correct doc count including the nested ones
> 
> curl -XGET [http://xx.xx.xx:9200/xx-20171212-1224/\_stats/docs?pretty](http://xx.xx.xx:9200/xx-20171212-1224/_stats/docs?pretty)

it the all number of docs?

---

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [December 28, 2017, 4:54am UTC](https://discuss.elastic.co/t/monitoring-data-not-same-with-curl-count-why/112532/13 "2017-12-28T04:54:36Z")

</div>

I didn't get you @zqc0512

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 25, 2018, 4:54am UTC](https://discuss.elastic.co/t/monitoring-data-not-same-with-curl-count-why/112532/14 "2018-01-25T04:54:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
