# Sliced scroll returning more hits than normal search (without slice)

**URL:** <https://discuss.elastic.co/t/sliced-scroll-returning-more-hits-than-normal-search-without-slice/314599>\
**Category:** Elasticsearch\
**Created:** [September 16, 2022, 7:26pm UTC](https://discuss.elastic.co/t/sliced-scroll-returning-more-hits-than-normal-search-without-slice/314599 "2022-09-16T19:26:57Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Divit\_Sharma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/divit_sharma/32/32348_2.png) [@Divit\_Sharma](https://discuss.elastic.co/u/Divit_Sharma)\
**Post date:** [September 16, 2022, 7:26pm UTC](https://discuss.elastic.co/t/sliced-scroll-returning-more-hits-than-normal-search-without-slice/314599/1 "2022-09-16T19:26:58Z")

</div>

In short, ` normal search hits < scroll slice 1 hits + scroll slice 2 hits`

When I add up sliced scroll hits, it is more than total no of documents returned from single search.

#### Normal search query

```auto
GET index*/_search
{
  "track_total_hits": true,
  "sort": [
    {
      "@timestamp": {
        "order": "asc",
        "unmapped_type": "boolean"
      }
    }
  ],
  "_source": false,
  "query": {
    "bool": {
      "must": [],
      "filter": [
        {
          "range": {
            "@timestamp": {
              "format": "strict_date_optional_time",
              "gte": "2022-07-31T18:30:00.000Z",
              "lte": "2022-08-30T18:30:00.000Z"
            }
          }
        }
.....

```

Normal Search Response:

```auto
{
  "took" : 1055,
  "timed_out" : false,
  "_shards" : {
    "total" : 455,
    "successful" : 455,
    "skipped" : 290,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 435743,
      "relation" : "eq"
    },
    "max_score" : null,

```

#### Slice 1

```auto
GET index*/_search
{ 
 "slice": {
    "id": 0,
    "max": 2
  },
  "track_total_hits": true,
  "sort": [
    {
      "@timestamp": {
        "order": "asc",
        "unmapped_type": "boolean"
      }
    }
  ],
  "_source": false,
  "query": {
    "bool": {
      "must": [],
      "filter": [
        {
          "range": {
            "@timestamp": {
              "format": "strict_date_optional_time",
              "gte": "2022-07-31T18:30:00.000Z",
              "lte": "2022-08-30T18:30:00.000Z"
            }
          }
        }
.....

```

Slice 1 Response:

```auto
  "_shards" : {
    "total" : 455,
    "successful" : 455,
    "skipped" : 290,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 213954,
      "relation" : "eq"
    },
    "max_score" : null,

```

#### Slice 2

```auto
GET index*/_search
{ 
 "slice": {
    "id": 1,
    "max": 2
  },
  "track_total_hits": true,
  "sort": [
    {
      "@timestamp": {
        "order": "asc",
        "unmapped_type": "boolean"
      }
    }
  ],
  "_source": false,
  "query": {
    "bool": {
      "must": [],
      "filter": [
        {
          "range": {
            "@timestamp": {
              "format": "strict_date_optional_time",
              "gte": "2022-07-31T18:30:00.000Z",
              "lte": "2022-08-30T18:30:00.000Z"
            }
          }
        }
.....

```

Slice 2 Response:

```auto
  "_shards" : {
    "total" : 455,
    "successful" : 455,
    "skipped" : 292,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 221884,
      "relation" : "eq"
    },
    "max_score" : null,

```

So as we can see,

total hits for slices = 213954 + 221884 = `435838` which is greater than `435743` (hits for normal search).

Can someone explain why is it behaving like this?

FYI, data is not being inserted/deleted. I am querying multiple indexes (index1, index2 ...) in this example.

`Version: 7.16.3`

---

<div class="post-metadata">

**Author:** ![Divit\_Sharma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/divit_sharma/32/32348_2.png) [@Divit\_Sharma](https://discuss.elastic.co/u/Divit_Sharma)\
**Post date:** [September 20, 2022, 7:28pm UTC](https://discuss.elastic.co/t/sliced-scroll-returning-more-hits-than-normal-search-without-slice/314599/2 "2022-09-20T19:28:14Z")

</div>

Can anyone help? This could be a bug.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [September 21, 2022, 11:59am UTC](https://discuss.elastic.co/t/sliced-scroll-returning-more-hits-than-normal-search-without-slice/314599/3 "2022-09-21T11:59:41Z")

</div>

It could. Or may be you index is not "stable" and you have been injected new documents after the first search?

---

<div class="post-metadata">

**Author:** ![Divit\_Sharma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/divit_sharma/32/32348_2.png) [@Divit\_Sharma](https://discuss.elastic.co/u/Divit_Sharma)\
**Post date:** [September 21, 2022, 2:36pm UTC](https://discuss.elastic.co/t/sliced-scroll-returning-more-hits-than-normal-search-without-slice/314599/4 "2022-09-21T14:36:03Z")

</div>

No, that is not the case. I can run it again and count for the normal search is same `435743` as when I first ran it few days ago.

Count values for 2 slices remains the same as when I first ran it i.e. `213954` + `221884` = `435838` but is different than normal search count total `435743`.

Different slice values gives different total count like for 3 slices count is `146602` + `155805` + `143114` = `445521`.

Is this due to the value used for **sort**?

FYI, this search is made to many indexes as you can see from `shards.total`. **For single index, slice is behaving fine.**

 ![Untitled](https://us1.discourse-cdn.com/elastic/original/3X/8/a/8a017038129eb2f3d75526bafa0c69459f2d7035.jpeg)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 19, 2022, 2:36pm UTC](https://discuss.elastic.co/t/sliced-scroll-returning-more-hits-than-normal-search-without-slice/314599/5 "2022-10-19T14:36:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
