# When aggregated by terms the value is incorrect

**URL:** <https://discuss.elastic.co/t/when-aggregated-by-terms-the-value-is-incorrect/150379>\
**Category:** Kibana\
**Created:** [September 28, 2018, 6:35pm UTC](https://discuss.elastic.co/t/when-aggregated-by-terms-the-value-is-incorrect/150379 "2018-09-28T18:35:09Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![jasmine.liang](https://avatars.discourse-cdn.com/v4/letter/j/bc79bd/32.png) [@jasmine.liang](https://discuss.elastic.co/u/jasmine.liang)\
**Post date:** [September 28, 2018, 6:35pm UTC](https://discuss.elastic.co/t/when-aggregated-by-terms-the-value-is-incorrect/150379/1 "2018-09-28T18:35:09Z")

</div>

I am trying to create a visualization and found the aggregated value is different when split by terms.  
The query is like this.

```
{
  "size": 0,
  "query": {
    "query_string": {
            "query": "*"
          }
  },
  "aggs": {
    "2": {
      "terms": {
        "field": "store_nbr",
        "size": 30,
        "order": {
          "1": "desc"
        }
      },
      "aggs": {
        "1": {
          "sum": {
            "field": "amt"
          }
        }
      }
    }
  }
}

```

And one of the return amt value for store\_nbr is

> ```
> {
> "1": {
> "value": 16953.470004558563
> },
> "key": 5408,
> "doc_count": 14
> }
> 
> ```
> 
> }

But when I query only for this 5408, it gives me  
`

> ```
> {
> "1": {
> "value": 21818.200009822845
> },
> "key": 5408,
> "doc_count": 51
> }
> 
> ```

The number is off. It looks like the doc\_count is also different. And I also found "doc\_count\_error\_upper\_bound" from the response is -1 with the terms.

How is this happened? And is there any way to solve this?

Thanks!!

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [October 1, 2018, 2:40pm UTC](https://discuss.elastic.co/t/when-aggregated-by-terms-the-value-is-incorrect/150379/2 "2018-10-01T14:40:57Z")

</div>

Hey @jasmine.liang, the doc counts for terms aggregations are approximate per [https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#search-aggregations-bucket-terms-aggregation-approximate-counts](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#search-aggregations-bucket-terms-aggregation-approximate-counts)

---

<div class="post-metadata">

**Author:** ![jasmine.liang](https://avatars.discourse-cdn.com/v4/letter/j/bc79bd/32.png) [@jasmine.liang](https://discuss.elastic.co/u/jasmine.liang)\
**Post date:** [October 1, 2018, 5:37pm UTC](https://discuss.elastic.co/t/when-aggregated-by-terms-the-value-is-incorrect/150379/3 "2018-10-01T17:37:38Z")

</div>

Thanks Brandon!

This document really explain what happened!

Then is there any way to solve this by enlarge memory or shard size temporally? Like anything to put into advanced JSON place to show more accurate results?

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [October 1, 2018, 6:48pm UTC](https://discuss.elastic.co/t/when-aggregated-by-terms-the-value-is-incorrect/150379/4 "2018-10-01T18:48:49Z")

</div>

Hey @jasmine.liang, you can use the advanced JSON similar to the following to adjust the "shard\_size" discussed [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#_shard_size_3).

```auto
{
"shard_size": 10
}

```

---

<div class="post-metadata">

**Author:** ![jasmine.liang](https://avatars.discourse-cdn.com/v4/letter/j/bc79bd/32.png) [@jasmine.liang](https://discuss.elastic.co/u/jasmine.liang)\
**Post date:** [October 10, 2018, 6:29pm UTC](https://discuss.elastic.co/t/when-aggregated-by-terms-the-value-is-incorrect/150379/5 "2018-10-10T18:29:08Z")

</div>

Thanks Brandon!. This really helps!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 7, 2018, 6:29pm UTC](https://discuss.elastic.co/t/when-aggregated-by-terms-the-value-is-incorrect/150379/6 "2018-11-07T18:29:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
