# Unclear aggregation results - version 5.3

**URL:** https://discuss.elastic.co/t/unclear-aggregation-results-version-5-3/148346
**Category:** Elasticsearch
**Created:** [September 12, 2018, 3:02pm UTC](https://discuss.elastic.co/t/unclear-aggregation-results-version-5-3/148346 "2018-09-12T15:02:50Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![liorg2](https://avatars.discourse-cdn.com/v4/letter/l/ed8c4c/32.png) [@liorg2](https://discuss.elastic.co/u/liorg2)
#### Post date: [September 12, 2018, 3:02pm UTC](https://discuss.elastic.co/t/unclear-aggregation-results-version-5-3/148346/1 "2018-09-12T15:02:50Z")

</div>

can anyone please explain why I'm getting these 2 buckets when running the given query?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/e/bec0cb1f2c05ac9a88682ae0b924e1f58a367f2a.png)

---

<div class="post-metadata">

### Author: ![jaddison](https://avatars.discourse-cdn.com/v4/letter/j/e5b9ba/32.png) [@jaddison](https://discuss.elastic.co/u/jaddison)
#### Post date: [September 12, 2018, 3:32pm UTC](https://discuss.elastic.co/t/unclear-aggregation-results-version-5-3/148346/2 "2018-09-12T15:32:41Z")

</div>

If I were to guess, I would say it is timezone-related. Try changing your query to include `Z` at the end (or otherwise make your `range` query use UTC timezone).

---

<div class="post-metadata">

### Author: ![liorg2](https://avatars.discourse-cdn.com/v4/letter/l/ed8c4c/32.png) [@liorg2](https://discuss.elastic.co/u/liorg2)
#### Post date: [September 13, 2018, 7:11am UTC](https://discuss.elastic.co/t/unclear-aggregation-results-version-5-3/148346/3 "2018-09-13T07:11:50Z")

</div>

your guess makes sense to me as well, but this gives the same result:

```
"range": {
  "date_time": {
    "gte": "2018-09-10T00:00:00.000Z",
    "lte": "2018-09-10T05:00:00.000Z"
  }
}
```

---

<div class="post-metadata">

### Author: ![jimczi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jimczi/32/47985_2.png) [@jimczi](https://discuss.elastic.co/u/jimczi)
#### Post date: [September 13, 2018, 8:22am UTC](https://discuss.elastic.co/t/unclear-aggregation-results-version-5-3/148346/4 "2018-09-13T08:22:07Z")

</div>

The intervals for the `date_histogram` starts at epoch time (1970-01-01T00:00:00) then for each date found in the documents we apply `(time_in_millis / interval_in_millis) * interval_in_millis`. By default all dates are considered UTC so `2018-09-10T00:00:00` falls into the `2018-09-09T23:00:00` bucket. You can use `"offset": "+1h"` in your `date_histogram` if you want to return buckets that start exactly at your `range` query boundaries but this would only work for this specific day. The `range` query filters documents but it doesn't change the way buckets are computed in the `date_histogram`.

---

<div class="post-metadata">

### Author: ![colings86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/colings86/32/44960_2.png) [@colings86](https://discuss.elastic.co/u/colings86)
#### Post date: [September 13, 2018, 8:29am UTC](https://discuss.elastic.co/t/unclear-aggregation-results-version-5-3/148346/5 "2018-09-13T08:29:03Z")

</div>

The date histogram aggregation (or any aggregation for that matter) does not base its bucket boundaries on the details of the query. This would end up being too complex as the bounds of a query could be buried deep within a complex query with many nested levels. Instead the aggregation is fed documents that match the query and evaluates them independently of the query. This allows use to keep aggregations easily composable and nestable without the risk that a small change to a query or a parent aggregationwill break other aggregations.

The boundaries for buckets for the date histogram aggregation when using an interval like `5h` are calculated by taking the epoch\_millis value of the date (so `2018-09-10T00:00:00` has an epoch\_millis value of `1536537600000`) and dividing it by the number of milliseconds in the intervals (assuming a fixed-duration interval rather than a calendar interval, in this case the interval millis for `5h` are `1000 * 60 * 60 * 5 = 18000000`), rounding down to the nearest integer (`1536537600000 / 18000000 = 85363.2` which rounds down to `85363`) and then multiplying that value by the interval again to obtain the bucket boundary (`85363 * 18000000 = 1536534000000` which is `2018-09-09T23:00:00`).

---

<div class="post-metadata">

### Author: ![liorg2](https://avatars.discourse-cdn.com/v4/letter/l/ed8c4c/32.png) [@liorg2](https://discuss.elastic.co/u/liorg2)
#### Post date: [September 27, 2018, 8:38am UTC](https://discuss.elastic.co/t/unclear-aggregation-results-version-5-3/148346/6 "2018-09-27T08:38:02Z")

</div>

thanks so much  
so the data of the '2018-09-09T23:00:00' bucket,with 5h interval summarize the period 2018-09-09T23:00:00 to 2018-09-10T04:00:00 ?

---

<div class="post-metadata">

### Author: ![liorg2](https://avatars.discourse-cdn.com/v4/letter/l/ed8c4c/32.png) [@liorg2](https://discuss.elastic.co/u/liorg2)
#### Post date: [September 27, 2018, 8:46am UTC](https://discuss.elastic.co/t/unclear-aggregation-results-version-5-3/148346/7 "2018-09-27T08:46:51Z")

</div>

and is there any option to achieve the requested query?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 25, 2018, 8:46am UTC](https://discuss.elastic.co/t/unclear-aggregation-results-version-5-3/148346/8 "2018-10-25T08:46:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
