# Search query on elasticsearch returning different output every time

**URL:** <https://discuss.elastic.co/t/search-query-on-elasticsearch-returning-different-output-every-time/199818>\
**Category:** Elasticsearch\
**Created:** [September 17, 2019, 12:20pm UTC](https://discuss.elastic.co/t/search-query-on-elasticsearch-returning-different-output-every-time/199818 "2019-09-17T12:20:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![amol\_sonawane1](https://avatars.discourse-cdn.com/v4/letter/a/e95f7d/32.png) [@amol\_sonawane1](https://discuss.elastic.co/u/amol_sonawane1)\
**Post date:** [September 17, 2019, 12:20pm UTC](https://discuss.elastic.co/t/search-query-on-elasticsearch-returning-different-output-every-time/199818/1 "2019-09-17T12:20:08Z")

</div>

Hi,

I am facing weird issue on Elasticsearch 6.7.0  
Our Elasticsearch cluster is a two-node cluster. which is refreshed daily through automation. The ES nodes are created daily and pushed data to ES from java app.

Some time we observed that the search queries are returning different output if we run in 1 sec interval.

Search query:  
POST /event\_index\_1/\_search  
{  
"size": 100,  
"query": {  
"terms": {  
"attributes.customUniqueID": [  
"event-335629.1d80447f.0"  
]  
}  
}  
}

The attributes.customUniqueID field is unique for the documents. So this search query should return one document every time.  
If the search query runs the first time then it will return 1 document. On the second execution of search query after 1 or 2 second it will return 0 documents. Again on third execution, it returns 1 document as same as first execution.

The output changes every time when we run the search query from 1 document to 0 documents.

The index created with 10 shards and 1 replica.

Does anyone observe the same issue?

Is there any issue with primary and replica shards mismatch??

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 17, 2019, 3:38pm UTC](https://discuss.elastic.co/t/search-query-on-elasticsearch-returning-different-output-every-time/199818/2 "2019-09-17T15:38:10Z")

</div>

You can use a `routing` option to ensure you are querying the same shards for testing, see [https://www.elastic.co/guide/en/elasticsearch/reference/7.3/search.html#search-routing](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/search.html#search-routing)

this would allow you to figure out, if this is the problem.

Also can you share the `_cat/shards/event_index_1` output?

---

<div class="post-metadata">

**Author:** ![amol\_sonawane1](https://avatars.discourse-cdn.com/v4/letter/a/e95f7d/32.png) [@amol\_sonawane1](https://discuss.elastic.co/u/amol_sonawane1)\
**Post date:** [October 4, 2019, 9:40am UTC](https://discuss.elastic.co/t/search-query-on-elasticsearch-returning-different-output-every-time/199818/3 "2019-10-04T09:40:20Z")

</div>

> [@spinscale](#):
>
> \_cat/shards/event\_index\_1

Output for `_cat/shards/event_index_1`  
event\_index\_1 1 r STARTED 2 9.6kb node1\_ip I-qrPxk  
event\_index\_1 1 p STARTED 2 9.6kb node2\_ip j2TL94D  
event\_index\_1 3 r STARTED 832 1.7mb node1\_ip I-qrPxk  
event\_index\_1 3 p STARTED 832 1.6mb node2\_ip j2TL94D  
event\_index\_1 9 r STARTED 3 14.5kb node1\_ip I-qrPxk  
event\_index\_1 9 p STARTED 2 8kb node2\_ip j2TL94D  
event\_index\_1 8 r STARTED 1 6.7kb node1\_ip I-qrPxk  
event\_index\_1 8 p STARTED 1 6.7kb node2\_ip j2TL94D  
event\_index\_1 4 r STARTED 1 6.6kb node1\_ip I-qrPxk  
event\_index\_1 4 p STARTED 0 261b node2\_ip j2TL94D  
event\_index\_1 2 r STARTED 2 9.7kb node1\_ip I-qrPxk  
event\_index\_1 2 p STARTED 2 9.7kb node2\_ip j2TL94D  
event\_index\_1 6 r STARTED 0 261b node1\_ip I-qrPxk  
event\_index\_1 6 p STARTED 0 261b node2\_ip j2TL94D  
event\_index\_1 5 r STARTED 1 7.3kb node1\_ip I-qrPxk  
event\_index\_1 5 p STARTED 1 7.3kb node2\_ip j2TL94D  
event\_index\_1 7 r STARTED 3 82.1kb node1\_ip I-qrPxk  
event\_index\_1 7 p STARTED 3 82.1kb node2\_ip j2TL94D  
event\_index\_1 0 r STARTED 3 81.5kb node1\_ip I-qrPxk  
event\_index\_1 0 p STARTED 0 261b node2\_ip j2TL94D

Also tried solution provided in below link. Still no luck.

> [@amol\_sonawane1](#):
>
> POST /event\_index\_1/\_search  
> {

> **[Search APIs | Elasticsearch Guide \[7.3\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/search.html#search-routing)**

Modified query based on solution given in link  
Search query:  
POST /event\_index\_1/\_search?routing=event-335629parent  
{  
"size": 100,  
"query": {  
"terms": {  
"attributes.customUniqueID": [  
"event-335629.1d80447f.0"  
]  
}  
}  
}

where event-335629parent is the parent id for the docunment and rounting provided while indexing the document.

---

<div class="post-metadata">

**Author:** ![amol\_sonawane1](https://avatars.discourse-cdn.com/v4/letter/a/e95f7d/32.png) [@amol\_sonawane1](https://discuss.elastic.co/u/amol_sonawane1)\
**Post date:** [October 5, 2019, 9:28am UTC](https://discuss.elastic.co/t/search-query-on-elasticsearch-returning-different-output-every-time/199818/4 "2019-10-05T09:28:34Z")

</div>

One more observation:

I have stopped both the nodes.  
Started both node individually ( nodes not running in same cluster). Executed the search query on both node separately and observed that ES returning the document for only one node where the replica shards are available. Not getting the document on node where the primary shards are presents.

Is it the replica out of sync issue??  
if yes the what is the solution for this. And what the reason for replica out of sync issue

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 2, 2019, 9:28am UTC](https://discuss.elastic.co/t/search-query-on-elasticsearch-returning-different-output-every-time/199818/5 "2019-11-02T09:28:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
