# Query hit count and query with aggregations don't match

**URL:** https://discuss.elastic.co/t/query-hit-count-and-query-with-aggregations-dont-match/34993
**Category:** Elasticsearch
**Created:** [November 18, 2015, 8:42pm UTC](https://discuss.elastic.co/t/query-hit-count-and-query-with-aggregations-dont-match/34993 "2015-11-18T20:42:47Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Karl\_Putland](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karl_putland/32/719_2.png) [@Karl\_Putland](https://discuss.elastic.co/u/Karl_Putland)
#### Post date: [November 18, 2015, 8:42pm UTC](https://discuss.elastic.co/t/query-hit-count-and-query-with-aggregations-dont-match/34993/1 "2015-11-18T20:42:47Z")

</div>

I'd like to see the aggregation over the entire index. Really what is of interest is utilization of the fields, but the query with the aggregation returns only a subset of the 2.7m records.

```
>>> r = es.search(index='cdr-2015.11.17', search_type='count', body={ 'query': {'match_all':{}}}, timeout=120, size=5000000)
>>> r
{u'hits': {u'hits': [], u'total': 2684630, u'max_score': 0.0}, u'_shards': {u'successful': 3, u'failed': 0, u'total': 3}, u'took': 35, u'timed_out': False}
>>> r = es.search(index='cdr-2015.11.17', search_type='count', body={ 'query': {'match_all':{}}, 'aggs': {
                        'missing_origination_egress_packets': {'missing': {'field': u'@fields.origination_egress_packets'}},
                        'missing_centrex_cfaDeactivation_facResult': {'missing': {'field': u'@fields.centrex_cfaDeactivation_facResult'}},
                        'missing_centrex_executiveAssistantOptOut_facResult': {'missing': {'field': u'@fields.centrex_executiveAssistantOptOut_facResult'}}} }, timeout=120, size=5000000)
>>> r['hits']['total']
14017
>>>
```

---

<div class="post-metadata">

### Author: ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)
#### Post date: [November 19, 2015, 2:51pm UTC](https://discuss.elastic.co/t/query-hit-count-and-query-with-aggregations-dont-match/34993/2 "2015-11-19T14:51:59Z")

</div>

Can you check that there were no shard failures and that you did not hit the timeout?

---

<div class="post-metadata">

### Author: ![Karl\_Putland](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karl_putland/32/719_2.png) [@Karl\_Putland](https://discuss.elastic.co/u/Karl_Putland)
#### Post date: [November 19, 2015, 3:50pm UTC](https://discuss.elastic.co/t/query-hit-count-and-query-with-aggregations-dont-match/34993/3 "2015-11-19T15:50:27Z")

</div>

On Thu, Nov 19, 2015 at 8:02 AM, Adrien Grand [noreply@discuss.elastic.co](mailto:noreply@discuss.elastic.co) wrote:

> timeout=120

query with aggregation has a took of ~650.

total changes from run to run on the query.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 11:37pm UTC](https://discuss.elastic.co/t/query-hit-count-and-query-with-aggregations-dont-match/34993/4 "2017-07-05T23:37:09Z")

</div>


