# Strange results when trying to run an aggregration query

**URL:** <https://discuss.elastic.co/t/strange-results-when-trying-to-run-an-aggregration-query/308100>\
**Category:** Elasticsearch\
**Created:** [June 24, 2022, 10:50am UTC](https://discuss.elastic.co/t/strange-results-when-trying-to-run-an-aggregration-query/308100 "2022-06-24T10:50:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![gep13](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gep13/32/107542_2.png) [@gep13](https://discuss.elastic.co/u/gep13)\
**Post date:** [June 24, 2022, 10:50am UTC](https://discuss.elastic.co/t/strange-results-when-trying-to-run-an-aggregration-query/308100/1 "2022-06-24T10:50:10Z")

</div>

Hello,

I am trying to run a query similar to the following:

```auto
  "aggs": {
    "authors": {
      "terms": {
        "field": "packageAuthors.keyword"
      }
    }
  }

```

Initially, this seems to be working exactly as I would expect it to. Within the results that are returned, one of the aggregated values comes back with:

```auto
        {
          "key" : "Gary Ewan Park",
          "doc_count" : 8
        }

```

Now to me, this meant that from the query that was returned, there were 8 documents that contained `Gary Ewan Park` as an author. However, I know that this is not the case, there are 9 documents that contain this author.

After testing, I found that I could get the aggregation query to return the correct value by changing it to the following:

```auto
  "aggs": {
    "authors": {
      "terms": {
        "field": "packageAuthors.keyword",
        "size": 1000
      }
    }
  }

```

Notice the addition of the `size` property. I thought that the size property only controlled the number of the aggregated values that would be returned, but it seems to be having more of an effect than I understood. Can someone explain what is going on here?

This is my first time posting in this forum, so if this is not the correct place to post this question, please let me know.

Thanks  
Gary

---

<div class="post-metadata">

**Author:** ![xeraa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xeraa/32/48181_2.png) [@xeraa](https://discuss.elastic.co/u/xeraa)\
**Post date:** [June 25, 2022, 9:30pm UTC](https://discuss.elastic.co/t/strange-results-when-trying-to-run-an-aggregration-query/308100/2 "2022-06-25T21:30:58Z")

</div>

[`shard_size`](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#search-aggregations-bucket-terms-aggregation-shard-size) is what you're after. It's a tradeoff between performance and accuracy with multiple shards (in a distributed system).

That `size` is having an impact on this is a side-effect since `shard_size` is calculated based on `size`.

PS: This is one of multiple tradeoffs between performance and accuracy in Elasticsearch; I have a presentation on these with three examples and what you ran into is the first one: [Make Your Data FABulous](https://xeraa.net/talks/make-your-data-fabulous/)

---

<div class="post-metadata">

**Author:** ![gep13](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gep13/32/107542_2.png) [@gep13](https://discuss.elastic.co/u/gep13)\
**Post date:** [June 27, 2022, 7:20am UTC](https://discuss.elastic.co/t/strange-results-when-trying-to-run-an-aggregration-query/308100/3 "2022-06-27T07:20:41Z")

</div>

Thank you for taking the time to respond here, and also on Twitter, really appreciate it!

We don't have _that_ much data, compared to other folks, so dropping to a single shard seems like the correct approach for us that the minute. Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 25, 2022, 7:21am UTC](https://discuss.elastic.co/t/strange-results-when-trying-to-run-an-aggregration-query/308100/4 "2022-07-25T07:21:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
