# Wrong data aggregation in a table

**URL:** https://discuss.elastic.co/t/wrong-data-aggregation-in-a-table/212033
**Category:** Kibana
**Created:** [December 16, 2019, 4:17pm UTC](https://discuss.elastic.co/t/wrong-data-aggregation-in-a-table/212033 "2019-12-16T16:17:20Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![Anne\_Kim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anne_kim/32/47196_2.png) [@Anne\_Kim](https://discuss.elastic.co/u/Anne_Kim)
#### Post date: [December 16, 2019, 4:17pm UTC](https://discuss.elastic.co/t/wrong-data-aggregation-in-a-table/212033/1 "2019-12-16T16:17:20Z")

</div>

Hello,  
I've created a table, but the data in the table differ from the elastic.  
For example, for player\_id "750" there are 6 records from 2 different devices:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/9/7/9785bdad8e320357d10fc065e12f3e3a422e7be3.png)  
However it's impossible because each player's id is uniquely connected with a device: 1 device = 1 player\_id and and vice versa. In Elastic with the id = 750 only one device is connected:  
 ![](https://us1.discourse-cdn.com/elastic/original/3X/d/a/da99d51373927d050f44f71365b6856b1daff117.png)  
The same problem I've encountered at various IDs: e.g., id 744. In a data table we see 5 different devices connected with the id:  
 ![](https://us1.discourse-cdn.com/elastic/original/3X/7/3/73bd717d46ec70c356bd9693ced8f8078f10d2b1.png)  
But in Elastic there is only one device:  
 ![](https://us1.discourse-cdn.com/elastic/original/3X/5/5/55358e10911bb4e3a9f541af18d7637109665050.png)

What it can be caused by? Recently I've updated Kibana from 7.3 up to 7.4, so can the problem be connected either with the Kibana 7.4 version or with the incorrect upgrade from my side?

Below I attach the request of the table vizualization:

```auto
{
  "aggs": {
    "2": {
      "terms": {
        "field": "device.keyword",
        "order": {
          "1": "desc"
        },
        "missing": " __missing__",
        "size": 5000
      },
      "aggs": {
        "1": {
          "avg": {
            "field": "stage_duration"
          }
        },
        "3": {
          "histogram": {
            "field": "player_id",
            "interval": 6,
            "min_doc_count": 1
          },
          "aggs": {
            "7": {
              "histogram": {
                "field": "tutorial_id",
                "interval": 5,
                "min_doc_count": 1
              },
              "aggs": {
                "6": {
                  "histogram": {
                    "field": "stage_id",
                    "interval": 1,
                    "min_doc_count": 0
                  },
                  "aggs": {
                    "4": {
                      "terms": {
                        "field": "completed",
                        "order": {
                          "1": "desc"
                        },
                        "size": 5
                      },
                      "aggs": {
                        "1": {
                          "avg": {
                            "field": "stage_duration"
                          }
                        },
                        "5": {
                          "terms": {
                            "field": "created_at",
                            "order": {
                              "1": "desc"
                            },
                            "size": 50
                          },
                          "aggs": {
                            "1": {
                              "avg": {
                                "field": "stage_duration"
                              }
                            }
                          }
                        }
                      }
                    }
                  }
                }
              }
            }
          }
        }
      }
    }
  },
  "size": 0,
  "_source": {
    "excludes": []
  },
  "stored_fields": [
    "*"
  ],
  "script_fields": {},
  "docvalue_fields": [
    {
      "field": "created_at",
      "format": "date_time"
    },
    {
      "field": "player_created_at",
      "format": "date_time"
    }
  ],
  "query": {
    "bool": {
      "must": [],
      "filter": [
        {
          "bool": {
            "filter": [
              {
                "bool": {
                  "should": [
                    {
                      "match": {
                        "is_tester": false
                      }
                    }
                  ],
                  "minimum_should_match": 1
                }
              },
              {
                "bool": {
                  "should": [
                    {
                      "match": {
                        "build": "0.3.0.1650"
                      }
                    }
                  ],
                  "minimum_should_match": 1
                }
              }
            ]
          }
        },
        {
          "range": {
            "stage_id": {
              "gte": 16,
              "lt": 19
            }
          }
        },
        {
          "range": {
            "created_at": {
              "format": "strict_date_optional_time",
              "gte": "2019-12-10T22:00:00.000Z",
              "lte": "2019-12-13T21:30:00.000Z"
            }
          }
        }
      ],
      "should": [],
      "must_not": []
    }
  }
}

```

---

<div class="post-metadata">

### Author: ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)
#### Post date: [December 16, 2019, 4:50pm UTC](https://discuss.elastic.co/t/wrong-data-aggregation-in-a-table/212033/2 "2019-12-16T16:50:23Z")

</div>

If you want to build a table using individual documents without aggregation, you should save the table you see in Discover and then embed that in a dashboard.

---

<div class="post-metadata">

### Author: ![Anne\_Kim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anne_kim/32/47196_2.png) [@Anne\_Kim](https://discuss.elastic.co/u/Anne_Kim)
#### Post date: [December 16, 2019, 5:05pm UTC](https://discuss.elastic.co/t/wrong-data-aggregation-in-a-table/212033/3 "2019-12-16T17:05:29Z")

</div>

I've built a table using data from elactic, as usual. And I see that the result doesnt correspond the reality.  
What do you mean by " build a table using **individual** documents"?

---

<div class="post-metadata">

### Author: ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)
#### Post date: [December 16, 2019, 5:17pm UTC](https://discuss.elastic.co/t/wrong-data-aggregation-in-a-table/212033/4 "2019-12-16T17:17:55Z")

</div>

The table you showed in the first screenshot is an aggregated table- it's not representing individual documents, so if you expect 1:1 correlation between the rows in the table and documents in Elasticsearch you can only do that with Discover

---

<div class="post-metadata">

### Author: ![Anne\_Kim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anne_kim/32/47196_2.png) [@Anne\_Kim](https://discuss.elastic.co/u/Anne_Kim)
#### Post date: [December 17, 2019, 10:29am UTC](https://discuss.elastic.co/t/wrong-data-aggregation-in-a-table/212033/5 "2019-12-17T10:29:38Z")

</div>

So can you explain please why the same request returns different results in aggregated table and in Discover? (data frame is the same)

---

<div class="post-metadata">

### Author: ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)
#### Post date: [December 17, 2019, 4:07pm UTC](https://discuss.elastic.co/t/wrong-data-aggregation-in-a-table/212033/6 "2019-12-17T16:07:13Z")

</div>

It's not the same request at all- try running the request in the Kibana dev tools and you'll see that it shows aggregated data, not individual documents

---

<div class="post-metadata">

### Author: ![Anne\_Kim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anne_kim/32/47196_2.png) [@Anne\_Kim](https://discuss.elastic.co/u/Anne_Kim)
#### Post date: [January 14, 2020, 2:20pm UTC](https://discuss.elastic.co/t/wrong-data-aggregation-in-a-table/212033/7 "2020-01-14T14:20:56Z")

</div>

The solution was to change the "player\_id" bucket type from **Histogram** to **Terms**

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 11, 2020, 2:21pm UTC](https://discuss.elastic.co/t/wrong-data-aggregation-in-a-table/212033/8 "2020-02-11T14:21:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
