# Strange (partly wrong?) numbers in results

**URL:** <https://discuss.elastic.co/t/strange-partly-wrong-numbers-in-results/38163>\
**Category:** Kibana\
**Created:** [December 30, 2015, 9:42am UTC](https://discuss.elastic.co/t/strange-partly-wrong-numbers-in-results/38163 "2015-12-30T09:42:55Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![moonwhaler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moonwhaler/32/6912_2.png) [@moonwhaler](https://discuss.elastic.co/u/moonwhaler)\
**Post date:** [December 30, 2015, 9:42am UTC](https://discuss.elastic.co/t/strange-partly-wrong-numbers-in-results/38163/1 "2015-12-30T09:42:56Z")

</div>

Hello there!

I'm using Kibana for some time now, testing a few a its analyzing features in our business environment which is based a lot on logistics and parcels. That being said, I tried to get an overview of shipped packages (packages:docs,1:1) based on a so called "shipment\_guid". I used a whole month as the search period and got 58 docs as a result which is fine based on the city (where the shipment was sent), BUT if I add the next filter "shipment type" (UPS, TNT, etc.) it still has 58 docs as a result, but displays "54" out of nowhere.

I already compared all results (in Discover) using different approaches e.g. filtering only unique results based on either the timestamp, shipment\_guid and other values, but the doc count has never been a "54".

Here's the request;

`{
  "query": {
    "filtered": {
      "query": {
        "query_string": {
          "analyze_wildcard": true,
          "query": "+receiver_street:*packstation* +contract:*ups*"
        }
      },
      "filter": {
        "bool": {
          "must": [
            {
              "$state": {
                "store": "globalState"
              },
              "query": {
                "match": {
                  "receiver_country_iso_alpha2": {
                    "query": "DE",
                    "type": "phrase"
                  }
                }
              }
            },
            {
              "query": {
                "match": {
                  "location.raw": {
                    "query": "Frankfurt",
                    "type": "phrase"
                  }
                }
              },
              "$state": {
                "store": "globalState"
              }
            },
            {
              "range": {
                "shipment_createdate_utc": {
                  "gte": 1448928000000,
                  "lte": 1451466944585,
                  "format": "epoch_millis"
                }
              }
            }
          ],
          "must_not": [
            {
              "$state": {
                "store": "globalState"
              },
              "query": {
                "match": {
                  "custship_method_id.raw": {
                    "query": "96",
                    "type": "phrase"
                  }
                }
              }
            }
          ]
        }
      }
    }
  },
  "size": 0,
  "aggs": {
    "4": {
      "terms": {
        "field": "location.raw",
        "size": 3,
        "order": {
          "1": "desc"
        }
      },
      "aggs": {
        "1": {
          "cardinality": {
            "field": "shipment_guid"
          }
        },
        "2": {
          "terms": {
            "field": "contract.raw",
            "size": 3,
            "order": {
              "1": "desc"
            }
          },
          "aggs": {
            "1": {
              "cardinality": {
                "field": "shipment_guid"
              }
            },
            "3": {
              "terms": {
                "field": "shipment_definition.raw",
                "size": 5,
                "order": {
                  "1": "desc"
                }
              },
              "aggs": {
                "1": {
                  "cardinality": {
                    "field": "shipment_guid"
                  }
                }
              }
            }
          }
        }
      }
    }
  }
}`

and here's the response:

`{
  "took": 27,
  "timed_out": false,
  "_shards": {
    "total": 4,
    "successful": 4,
    "failed": 0
  },
  "hits": {
    "total": 58,
    "max_score": 0,
    "hits": []
  },
  "aggregations": {
    "4": {
      "doc_count_error_upper_bound": 0,
      "sum_other_doc_count": 0,
      "buckets": [
        {
          "1": {
            "value": 58
          },
          "2": {
            "doc_count_error_upper_bound": 0,
            "sum_other_doc_count": 0,
            "buckets": [
              {
                "1": {
                  "value": 54
                },
                "3": {
                  "doc_count_error_upper_bound": 0,
                  "sum_other_doc_count": 0,
                  "buckets": [
                    {
                      "1": {
                        "value": 54
                      },
                      "key": "UPS Express Saver 12:00",
                      "doc_count": 58
                    }
                  ]
                },
                "key": "UPS Express",
                "doc_count": 58
              }
            ]
          },
          "key": "Frankfurt",
          "doc_count": 58
        }
      ]
    }
  }
}`

I'm a bit confused, since it still says "doc\_count: 58", but displays "value: 54" - at least in the "sub results".

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [December 30, 2015, 7:23pm UTC](https://discuss.elastic.co/t/strange-partly-wrong-numbers-in-results/38163/2 "2015-12-30T19:23:44Z")

</div>

From what I can tell you are right and the correct cardinality is 58. I would bet this is caused by the implementation of cardinality which makes it efficient, but also makes it an aproximation (as stated [in the docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-metrics-cardinality-aggregation.html)).

> A single-value metrics aggregation that calculates an approximate count of distinct values.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:05pm UTC](https://discuss.elastic.co/t/strange-partly-wrong-numbers-in-results/38163/3 "2017-07-06T14:05:49Z")

</div>


