# Why Kibana Dashboard values are different from index query

**URL:** <https://discuss.elastic.co/t/why-kibana-dashboard-values-are-different-from-index-query/334813>\
**Category:** Kibana\
**Created:** [May 31, 2023, 1:59pm UTC](https://discuss.elastic.co/t/why-kibana-dashboard-values-are-different-from-index-query/334813 "2023-05-31T13:59:54Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vitor\_Nilson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitor_nilson/32/119824_2.png) [@Vitor\_Nilson](https://discuss.elastic.co/u/Vitor_Nilson)\
**Post date:** [May 31, 2023, 1:59pm UTC](https://discuss.elastic.co/t/why-kibana-dashboard-values-are-different-from-index-query/334813/1 "2023-05-31T13:59:54Z")

</div>

Hello,

I have a index called `kong` (the main index), and a Rollup job in this index grouping every 24h which has a index calld `rollup_job_kong_gateway`.

If we take a look directely in the index Kong and run the following query:

```auto

GET kong/_search
{
  "size": 0, 
  "query": {
    
   "bool": {
     
     "must": [
     
    {"range": {
      "@timestamp": {
         "gte": "2023-05-28T00:00:00.000",
        "lte": "2023-05-30T00:00:00.000"
      }
    }}
    
    
     ]
   }
    
    
    
  },
  "aggs": {
    
      "daily_sum": {
      "date_histogram": {
        "field": "@timestamp",
        "calendar_interval": "1d"
      },
      
        
      "aggs": {
        "daily_count": {
          "value_count": {
            "field": "@timestamp"
          }
        }}
      
      
    },
    
    "count_total_requests": {
      "value_count": {
        "field": "@timestamp"
      }
    },
    "count_total_nome_integrador": {
      "cardinality": {
        "field": "nomeIntegrador.keyword"
      }
    }
    
  }
}

```

This is the result:

Day 2023-05-28 total of 1,428,413 requests  
Day 2023-05-29 total of 1,735,944 requests.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/d/ed93e54d4e0d2cf887055732112c5a748415398c.png)

And now if we execute the same query (just summing instead of counting) on the rollup index we have the same values:

```auto

GET rollup_job_kong_gateway/_search
{
   "size": 0, 
  "query": {
    
   "bool": {
     
     "must": [

    {"range": {
      "@timestamp.date_histogram.timestamp": {
        "gte": "2023-05-28T00:00:00.000",
        "lte": "2023-05-29T00:00:00.000"
      }
    }}
    
    
     ]
   }
    
    
  },
  "aggs": {
    
    "daily_sum": {
      "date_histogram": {
        "field": "@timestamp.date_histogram.timestamp",
        "calendar_interval": "1d"
      },
      
        
      "aggs": {
        "daily_count": {
          "sum": {
            "field": "@timestamp.date_histogram._count"
          }
        }}
      
      
    },
    
    
    
    "count_total_requests": {
          "sum": {
            "field": "@timestamp.date_histogram._count"
          }
    },
    "count_total_nome_integrador": {
          "cardinality": {
            "field": "nomeIntegrador.keyword.terms.value"
          }
        }
        
        
    
  }
}

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/5/f5cb87e0ae36eca99cbe0e1f05ef1b12eb517a7b.png)

What I can't understand is: Why Kibana dashboard is showing different values?

This is a dashboard on Kong (main index): `(Only day 28)`  
Why does it now only shows 1,436,142 instead of 1,428,413 that is in its index?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/f/efb95284573455c18d5ab3c568a07bc33b7ffd20.png)

If we take a look, it's just showing the total of records:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/c/0c29e628a2c72694108d53d97c43fc97417936fd.png)

And this is the Rollup Job Dashboard: `(Only day 28)`  
It shows the right value

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/2/7239c63769d63ac367bfb5deb75f970011950753.png)

If we take a look, it's just showing the total of records (by summing the count of timestamp):

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/1/c1f30a23c70f69674326387e6a8c918fe5e799d4.png)

I'm litte bit confused, if someone could help me I'd feel happy.

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [June 1, 2023, 10:54am UTC](https://discuss.elastic.co/t/why-kibana-dashboard-values-are-different-from-index-query/334813/2 "2023-06-01T10:54:35Z")

</div>

You can check what exactly queries your dashboard render with the `Inspect` tool on the top right bar. Have you checked it to compare queries requests and responses with your Console work?

---

<div class="post-metadata">

**Author:** ![Vitor\_Nilson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitor_nilson/32/119824_2.png) [@Vitor\_Nilson](https://discuss.elastic.co/u/Vitor_Nilson)\
**Post date:** [June 1, 2023, 11:20am UTC](https://discuss.elastic.co/t/why-kibana-dashboard-values-are-different-from-index-query/334813/3 "2023-06-01T11:20:24Z")

</div>

Wow, I found out why it never matchs.

On the dashboard I set the following range:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/a/9a54799e21ba85254a3b3c5c7df63f3b3fc15758.png)

And this is the request:

```auto
GET .....
{
  "aggs": {
    "0": {
      "sum": {
        "field": "@timestamp.date_histogram._count"
      }
    }
  },
  "size": 0,
  "fields": [
    {
      "field": "@timestamp.date_histogram.timestamp",
      "format": "date_time"
    }
  ],
  "script_fields": {},
  "stored_fields": [
    "*"
  ],
  "runtime_mappings": {},
  "_source": {
    "excludes": []
  },
  "query": {
    "bool": {
      "must": [],
      "filter": [
        {
          "range": {
            "@timestamp.date_histogram.timestamp": {
              "format": "strict_date_optional_time",
              "gte": "2023-05-28T03:00:00.000Z",
              "lte": "2023-05-29T03:00:00.000Z"
            }
          }
        }
      ],
      "should": [],
      "must_not": []
    }
  }
}

```

Why is it adding 3 hours to my selected range? Looks like it's getting my current timezone and formatting the date.

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [June 1, 2023, 11:27am UTC](https://discuss.elastic.co/t/why-kibana-dashboard-values-are-different-from-index-query/334813/4 "2023-06-01T11:27:14Z")

</div>

> [@Vitor\_Nilson](#):
>
> Looks like it's getting my current timezone and formatting the date.

That is standard Kibana behavior, yes. You can change i thoug through the Advanced Settings page on the `General` section to use a fixed time zone.

> **[Advanced Settings | Kibana Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/kibana/current/advanced-options.html#kibana-general-settings)**

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/e/ae3454ee562547443a3c39b0f0039833283ddb23.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 29, 2023, 11:27am UTC](https://discuss.elastic.co/t/why-kibana-dashboard-values-are-different-from-index-query/334813/5 "2023-06-29T11:27:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
