# Table shows a lot less than discovery or graph

**URL:** <https://discuss.elastic.co/t/table-shows-a-lot-less-than-discovery-or-graph/83573>\
**Category:** Kibana\
**Created:** [April 25, 2017, 1:41pm UTC](https://discuss.elastic.co/t/table-shows-a-lot-less-than-discovery-or-graph/83573 "2017-04-25T13:41:19Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![tomer](https://avatars.discourse-cdn.com/v4/letter/t/41988e/32.png) [@tomer](https://discuss.elastic.co/u/tomer)\
**Post date:** [April 25, 2017, 1:41pm UTC](https://discuss.elastic.co/t/table-shows-a-lot-less-than-discovery-or-graph/83573/1 "2017-04-25T13:41:19Z")

</div>

Hi

When I create a table to show all messages by timestamp I get a few bunches of messages but not all. Why is this? For here as an example in Discovery I see a message from 14:49:\*\* but in the table it does not appear.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/e/1/e1d8a3b984eb001773ee68bb026da903123f7a0c.png)

 ![](https://us1.discourse-cdn.com/elastic/original/3X/8/a/8ae4eeae36a5468c5665b20ff9ce051b481f9e23.png)

In the production mode I see a bunch of message that not one have a Count over 1, and still there are missing logs.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [April 25, 2017, 3:06pm UTC](https://discuss.elastic.co/t/table-shows-a-lot-less-than-discovery-or-graph/83573/2 "2017-04-25T15:06:46Z")

</div>

I don't fully understand what are you trying to achieve. Any reason why you are using a terms split on @timestamp field ? are you maybe looking for a date histogram agg ?

---

<div class="post-metadata">

**Author:** ![tomer](https://avatars.discourse-cdn.com/v4/letter/t/41988e/32.png) [@tomer](https://discuss.elastic.co/u/tomer)\
**Post date:** [April 25, 2017, 3:51pm UTC](https://discuss.elastic.co/t/table-shows-a-lot-less-than-discovery-or-graph/83573/3 "2017-04-25T15:51:17Z")

</div>

Hi,

This is not a real graph for production. I just wanted to simulate the idea that there are logs shown in "discovery" but not on the table. I used @timestamp just b/c it is easy to show that messages are missing from the table on a certain time.

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [April 25, 2017, 6:38pm UTC](https://discuss.elastic.co/t/table-shows-a-lot-less-than-discovery-or-graph/83573/4 "2017-04-25T18:38:39Z")

</div>

the data in your visualization is aggregated in buckets, so you will not see individual records as you do in discover.  
where in discover you would see each record for lets say a month of data, in visualization you would usually want to group them together in a way for example show a count per day.

---

<div class="post-metadata">

**Author:** ![tomer](https://avatars.discourse-cdn.com/v4/letter/t/41988e/32.png) [@tomer](https://discuss.elastic.co/u/tomer)\
**Post date:** [April 26, 2017, 10:28am UTC](https://discuss.elastic.co/t/table-shows-a-lot-less-than-discovery-or-graph/83573/5 "2017-04-26T10:28:46Z")

</div>

Thanks.

After I saw the problem I understood that my question was not defined good enough.

My problem was that I didnt define the size of logs that should be returned by table. By default it is 5:

![](https://us1.discourse-cdn.com/elastic/original/3X/2/4/24ce5da0fbc2f825728e9c9c766f51105ee5f963.png)

Thanks for the effort!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2017, 10:34am UTC](https://discuss.elastic.co/t/table-shows-a-lot-less-than-discovery-or-graph/83573/6 "2017-05-24T10:34:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
