# Top 10 Filtering Appears inconsistent

**URL:** <https://discuss.elastic.co/t/top-10-filtering-appears-inconsistent/172865>\
**Category:** Kibana\
**Created:** [March 18, 2019, 9:16pm UTC](https://discuss.elastic.co/t/top-10-filtering-appears-inconsistent/172865 "2019-03-18T21:16:31Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![daniel.eaton](https://avatars.discourse-cdn.com/v4/letter/d/48db29/32.png) [@daniel.eaton](https://discuss.elastic.co/u/daniel.eaton)\
**Post date:** [March 18, 2019, 9:16pm UTC](https://discuss.elastic.co/t/top-10-filtering-appears-inconsistent/172865/1 "2019-03-18T21:16:31Z")

</div>

Hi All,

Just had a Visualisation/Functionality question regarding Kibana's "Show Terms" functionality.

I am visualising the top 5 Customers (Text, Keyword) by Transaction Amount Total (Sum, Number).

When I limit the number of customers to be displayed to 5, (Based on Descending Sum of Transaction Amount). I get:  
Customer A (with 100k),  
Customer B (with 90k),  
Customer C (with 80k),  
Customer D (with 70k),  
Customer E (with 60k)  
(Aliased for privacy reasons).

However, When I expand this to double check my working, to the top 1000, the first 5 entries are no longer A, B, C, D, E, and are instead  
Customer A (100k),  
Customer J (95k),  
Customer B (90k),  
Customer M (88k),  
Customer Z (85k)

Any Idea why I would be getting incorrect information when i reduce the size of the Terms shown? I am using Customer\_Name.Keyword field as per below,

```
"Customer_Name": {
              "type": "text", 
              "fields": 
              {
                "keyword":
                {
                 "type":"keyword" 
                }
              }
            },
```

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [March 20, 2019, 5:03pm UTC](https://discuss.elastic.co/t/top-10-filtering-appears-inconsistent/172865/2 "2019-03-20T17:03:21Z")

</div>

Hmm, that's definitely strange. Have you looked at the request/response from Elasticsearch to see if that's the data coming back from Elasticsearch?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 20, 2019, 5:30pm UTC](https://discuss.elastic.co/t/top-10-filtering-appears-inconsistent/172865/3 "2019-03-20T17:30:43Z")

</div>

If you have a field with quite high cardinality I believe this is expected [as terms aggregations are approximate](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#search-aggregations-bucket-terms-aggregation-approximate-counts). How many customers do you have in the index? How many shards is this data distributed across?

---

<div class="post-metadata">

**Author:** ![daniel.eaton](https://avatars.discourse-cdn.com/v4/letter/d/48db29/32.png) [@daniel.eaton](https://discuss.elastic.co/u/daniel.eaton)\
**Post date:** [March 20, 2019, 6:20pm UTC](https://discuss.elastic.co/t/top-10-filtering-appears-inconsistent/172865/4 "2019-03-20T18:20:27Z")

</div>

1 Shard, 1 Replicate  
1000-2000 customers - 100,000 documents

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 20, 2019, 6:53pm UTC](https://discuss.elastic.co/t/top-10-filtering-appears-inconsistent/172865/5 "2019-03-20T18:53:07Z")

</div>

If all the data is in a single index with a single shard it sounds strange that it changes. Do the shards have the same number of documents if you look at the \_cat/shards API?

---

<div class="post-metadata">

**Author:** ![daniel.eaton](https://avatars.discourse-cdn.com/v4/letter/d/48db29/32.png) [@daniel.eaton](https://discuss.elastic.co/u/daniel.eaton)\
**Post date:** [March 20, 2019, 7:07pm UTC](https://discuss.elastic.co/t/top-10-filtering-appears-inconsistent/172865/6 "2019-03-20T19:07:50Z")

</div>

Sorry, I stand corrected, It somehow ended up on 5 shards (Primary)  
get \_cat/shards  
indx 2 p STARTED 20110 6.1mb 172.30.60.11 jpK1TfI  
indx 2 r UNASSIGNED  
indx 3 p STARTED 19863 5.7mb 172.30.60.11 jpK1TfI  
indx 3 r UNASSIGNED  
indx 1 p STARTED 20126 6.1mb 172.30.60.11 jpK1TfI  
indx 1 r UNASSIGNED  
indx 4 p STARTED 19770 5.7mb 172.30.60.11 jpK1TfI  
indx 4 r UNASSIGNED  
indx 0 p STARTED 20131 5.7mb 172.30.60.11 jpK1TfI  
indx 0 r UNASSIGNED

---

<div class="post-metadata">

**Author:** ![daniel.eaton](https://avatars.discourse-cdn.com/v4/letter/d/48db29/32.png) [@daniel.eaton](https://discuss.elastic.co/u/daniel.eaton)\
**Post date:** [March 20, 2019, 7:41pm UTC](https://discuss.elastic.co/t/top-10-filtering-appears-inconsistent/172865/7 "2019-03-20T19:41:16Z")

</div>

Was a difference because of the shards causing inaccuracies, resolved it !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 17, 2019, 7:41pm UTC](https://discuss.elastic.co/t/top-10-filtering-appears-inconsistent/172865/8 "2019-04-17T19:41:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
