I have two visualizations - both against the same saved search (and the same timeframe).
One is a Data table , that on top of some other summaries (which in this case includes all docs) , includes a Unique count metric of a not_analyzed field (host.ip) - which reports 314 unique ips.
The second is a simple Unique count metric visualization of the same field - however this visualization , which is not contrained by any other limitations , only reports 294 unique ips.
How is this possible ?
This is a test environment - running Elasticsearch and kibana on a single machine . no distributed shards or anything. Just ~3mil docs in a single index.