# Why would Kibana not show all docs?

**URL:** <https://discuss.elastic.co/t/why-would-kibana-not-show-all-docs/305187>\
**Category:** Kibana\
**Created:** [May 19, 2022, 12:26pm UTC](https://discuss.elastic.co/t/why-would-kibana-not-show-all-docs/305187 "2022-05-19T12:26:46Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [May 19, 2022, 12:26pm UTC](https://discuss.elastic.co/t/why-would-kibana-not-show-all-docs/305187/1 "2022-05-19T12:26:46Z")

</div>

I just created an index with 235 docs all created within the same second. In devtools a search returns all 235 docs, however Kibana, on the first screen before any filtering only returns 177.

I don't know where to look for the problem, any ideas?

Stack version is 8.1.3. Docs were created with Python API bulk with the current time for @timestamp and \_id was generated.

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [May 19, 2022, 1:16pm UTC](https://discuss.elastic.co/t/why-would-kibana-not-show-all-docs/305187/2 "2022-05-19T13:16:44Z")

</div>

> however Kibana, on the first screen before any filtering only returns 177.

What version of kibana are you running? What is the "first screen"? Kibana has lots of applications. If you are using Discover, have you tried opening "inspector"? That will show you the request/response for the data you are viewing

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [May 19, 2022, 2:00pm UTC](https://discuss.elastic.co/t/why-would-kibana-not-show-all-docs/305187/3 "2022-05-19T14:00:42Z")

</div>

Yes, discover version 8.1.3.

Request:

```auto
{
  "track_total_hits": false,
  "sort": [
    {
      "@timestamp": {
        "order": "desc",
        "unmapped_type": "boolean"
      }
    }
  ],
  "fields": [
    {
      "field": "*",
      "include_unmapped": "true"
    },
    {
      "field": "@timestamp",
      "format": "strict_date_optional_time"
    }
  ],
  "size": 500,
  "version": true,
  "script_fields": {},
  "stored_fields": [
    "*"
  ],
  "runtime_mappings": {},
  "_source": false,
  "query": {
    "bool": {
      "must": [],
      "filter": [
        {
          "range": {
            "@timestamp": {
              "format": "strict_date_optional_time",
              "gte": "2022-05-18T13:00:00.000Z",
              "lte": "2022-05-19T13:51:12.092Z"
            }
          }
        }
      ],
      "should": [],
      "must_not": []
    }
  },
  "highlight": {
    "pre_tags": [
      "@kibana-highlighted-field@"
    ],
    "post_tags": [
      "@/kibana-highlighted-field@"
    ],
    "fields": {
      "*": {}
    },
    "fragment_size": 2147483647
  }
}

```

Response trimmed of our data:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/6/06cfbd0827c3f22678e7e5bf6bb9c398c2a369df.png)  
...  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/d/4d87365c1c8eb90a7cbdca6a31a7758133f5cbe8.png)

Stats show 177 hits.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 19, 2022, 2:07pm UTC](https://discuss.elastic.co/t/why-would-kibana-not-show-all-docs/305187/4 "2022-05-19T14:07:50Z")

</div>

What is the result if you run the same Kibana query in dev tools?

```auto
GET your-index/_search
{
"query": {
    "bool": {
      "must": [],
      "filter": [
        {
          "range": {
            "@timestamp": {
              "format": "strict_date_optional_time",
              "gte": "2022-05-18T13:00:00.000Z",
              "lte": "2022-05-19T13:51:12.092Z"
            }
          }
        }
      ],
      "should": [],
      "must_not": []
    }
  }
}

```

Can you track a document that is appearing in dev tools but not in Kibana and share it?

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [May 19, 2022, 2:10pm UTC](https://discuss.elastic.co/t/why-would-kibana-not-show-all-docs/305187/5 "2022-05-19T14:10:24Z")

</div>

Ok, some have 1970 dates..... I'll have to see if it's an input or indexing error.

Thanks

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [May 19, 2022, 2:32pm UTC](https://discuss.elastic.co/t/why-would-kibana-not-show-all-docs/305187/6 "2022-05-19T14:32:15Z")

</div>

It looks like when the timestamp is "short", it's not indexing correctly.

![image](https://us1.discourse-cdn.com/elastic/original/3X/1/0/10237f2085707ad2af2c5c626e125c81b86bc79e.png)

@timestamp has mapping type of epoch\_millis and epoch\_second. I'm not sure which handles these with decimals.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 16, 2022, 2:33pm UTC](https://discuss.elastic.co/t/why-would-kibana-not-show-all-docs/305187/7 "2022-06-16T14:33:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
