# Transform group by showing data that's not in the original index

**URL:** <https://discuss.elastic.co/t/transform-group-by-showing-data-thats-not-in-the-original-index/301239>\
**Category:** Kibana\
**Created:** [March 31, 2022, 5:51pm UTC](https://discuss.elastic.co/t/transform-group-by-showing-data-thats-not-in-the-original-index/301239 "2022-03-31T17:51:56Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matt\_McGovern](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_mcgovern/32/90131_2.png) [@Matt\_McGovern](https://discuss.elastic.co/u/Matt_McGovern)\
**Post date:** [March 31, 2022, 5:51pm UTC](https://discuss.elastic.co/t/transform-group-by-showing-data-thats-not-in-the-original-index/301239/1 "2022-03-31T17:51:56Z")

</div>

I've got a tranform set up that has multiple group fields and aggregations. The first group by field shows data in the resulting index that is not anywhere in the original index. It starts with the text: deleterulebyrule-success|data: then follows with json. Is this something to do with the deleting of records because of the transform's retention?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 28, 2022, 5:52pm UTC](https://discuss.elastic.co/t/transform-group-by-showing-data-thats-not-in-the-original-index/301239/2 "2022-04-28T17:52:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
