# Unique Count Metric and Cardinality filter not providing the same result

**URL:** <https://discuss.elastic.co/t/unique-count-metric-and-cardinality-filter-not-providing-the-same-result/143863>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [August 10, 2018, 11:40am UTC](https://discuss.elastic.co/t/unique-count-metric-and-cardinality-filter-not-providing-the-same-result/143863 "2018-08-10T11:40:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![djuentgen](https://avatars.discourse-cdn.com/v4/letter/d/a5b964/32.png) [@djuentgen](https://discuss.elastic.co/u/djuentgen)\
**Post date:** [August 10, 2018, 11:40am UTC](https://discuss.elastic.co/t/unique-count-metric-and-cardinality-filter-not-providing-the-same-result/143863/1 "2018-08-10T11:40:37Z")

</div>

Hi,

in the first step i have set up some metric visualizations with in this case unique count on one specific field. As a next step i want to implement watcher on this field but the filter query is not providing the same result on the same filter ( for my understating they are equal).

my watcher filter is like:

```
		"adqry": {
              "search": {
                "request": {
                  "indices": [
                    "50005_myindex"
                  ],
                  "body": {
                    "query": {
                      "query_string": {
                        "query": "procname:adinfo AND _exists_:userprincipalname_hash AND NOT testevent:true AND -domain:/my.domain.+/ AND @timestamp:>now-24h"
                      }
                    },
                    "aggs": {
                      "type_count": {
                        "cardinality": {
                          "field": "userprincipalname_hash"
                        }
                      }
                    }
                  }
                }
              }
            }

```

The visualization is set up as follows:

1. saved a discover filtering: `procname:adinfo AND _exists_:userprincipalname_hash AND NOT testevent:true AND -domain:/my.domain.+/ AND @timestamp:>now-24h`
2. configured a metric visualizations refering on the prior saved discover with "metric-\> aggregation: unique count" and "field: principalusername\_hash"

My problem is, that the visualization provides: 72 623 as a unique count  
and the filter provides

> ctx.payload.adqry.hits.total: 75741

as a unique count  
and i dont know what is wrong.

many thanks in advance and a sunny weekend!

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 13, 2018, 7:11am UTC](https://discuss.elastic.co/t/unique-count-metric-and-cardinality-filter-not-providing-the-same-result/143863/2 "2018-08-13T07:11:21Z")

</div>

Hey,

can you just run the query in dev tools and see what is being returned? I'd assume the same value than the one from watcher (including some fluctuations, because every query is going to have a different `now`).

As watcher is only executing that search query, I assume there might be a slight difference with the search query.

Is it possible that you are using `Kuery` in kibana as your query language? That would not be supported in watcher/elasticsearch.

--Alex

---

<div class="post-metadata">

**Author:** ![djuentgen](https://avatars.discourse-cdn.com/v4/letter/d/a5b964/32.png) [@djuentgen](https://discuss.elastic.co/u/djuentgen)\
**Post date:** [August 13, 2018, 9:14am UTC](https://discuss.elastic.co/t/unique-count-metric-and-cardinality-filter-not-providing-the-same-result/143863/3 "2018-08-13T09:14:02Z")

</div>

Hey Alex,

thanks for the reply.

the problem forcing the deviation was caused by not referencing on the corect payload value.

i needed to get the value from the cardinality aggregation but my payload was fetching the total value of hits -\> `ctx.payload.adqry.hits.total` instead of the result of the aggregation -\> `ctx.payload.adqry.aggregations.count.value`

cheers, daniel

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 10, 2018, 9:14am UTC](https://discuss.elastic.co/t/unique-count-metric-and-cardinality-filter-not-providing-the-same-result/143863/4 "2018-09-10T09:14:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
