# Wrong results on Terms Aggregations

**URL:** <https://discuss.elastic.co/t/wrong-results-on-terms-aggregations/20774>\
**Category:** Elasticsearch\
**Created:** [November 17, 2014, 7:25am UTC](https://discuss.elastic.co/t/wrong-results-on-terms-aggregations/20774 "2014-11-17T07:25:12Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ananth](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@ananth](https://discuss.elastic.co/u/ananth)\
**Post date:** [November 17, 2014, 7:25am UTC](https://discuss.elastic.co/t/wrong-results-on-terms-aggregations/20774/1 "2014-11-17T07:25:12Z")

</div>

Hi,

I have two fields _request\_url (analysed)_ and \*url\_report (not\_analysed)  
. \*Both has the same content .

The index has only one shard. The following is the aggregations query ,

{"from": 0,"size": 0, "query": {  
"bool": {  
"must": {  
"query\_string": {  
"query": "request\_url:"login"",  
"default\_operator": "and"  
} } } },  
"aggregations": {  
"unique\_url\_report\_count": {  
"cardinality": {  
"field": "url\_report"  
}},  
"unique\_url\_report\_values": {  
"terms": {  
"field": "url\_report",  
"size": 1000  
}}}}

The ElasticSearch response is,

- took: 312 timed\_out: false
- \_shards: { total: 1 successful: 1 failed: 0}
- hits: {total: 5711 max\_score: 0 hits: []}
- aggregations: {
  - unique\_url\_report\_count: { value: 3}
  - unique\_url\_report\_values: {
  - 
## buckets: [

```
- { key: /login
   - doc_count: 5708
}
- {
- 
   - key: /ui/settings/login-history.jsp
   - doc_count: 2
}
- {
   - key: /home
   - doc_count: 1
}

```

]}}}

The first 2 buckets are ok since it has login , but the 3rd bucket seems  
wrong . Am i missing anything ?

- 
  - 

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/b725ab85-3fcb-4c3c-a8b1-f3eee20e6718%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/b725ab85-3fcb-4c3c-a8b1-f3eee20e6718%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [November 17, 2014, 10:27am UTC](https://discuss.elastic.co/t/wrong-results-on-terms-aggregations/20774/2 "2014-11-17T10:27:49Z")

</div>

Can you try to find the document that matched although it should not, and  
call the explain API on it to see why it matched?

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

On Mon, Nov 17, 2014 at 8:25 AM, Anantha Govindarajan \<  
[ananthagovindarajan@gmail.com](mailto:ananthagovindarajan@gmail.com)\> wrote:

> Hi,
> 
> I have two fields _request\_url (analysed)_ and \*url\_report  
> (not\_analysed) . \*Both has the same content .
> 
> The index has only one shard. The following is the aggregations query ,
> 
> {"from": 0,"size": 0, "query": {  
> "bool": {  
> "must": {  
> "query\_string": {  
> "query": "request\_url:"login"",  
> "default\_operator": "and"  
> } } } },  
> "aggregations": {  
> "unique\_url\_report\_count": {  
> "cardinality": {  
> "field": "url\_report"  
> }},  
> "unique\_url\_report\_values": {  
> "terms": {  
> "field": "url\_report",  
> "size": 1000  
> }}}}
> 
> The Elasticsearch response is,
> 
> - took: 312 timed\_out: false
> - \_shards: { total: 1 successful: 1 failed: 0}
> - hits: {total: 5711 max\_score: 0 hits: }
> - aggregations: {
> - unique\_url\_report\_count: { value: 3}
> - unique\_url\_report\_values: {
> - 
> ## buckets: [
> 
> ```
> - { key: /login
> - doc_count: 5708
> }
> - {
> -
> - key: /ui/settings/login-history.jsp
> - doc_count: 2
> }
> - {
> - key: /home
> - doc_count: 1
> }
> 
> ```
> 
> ]}}}
> 
> The first 2 buckets are ok since it has login , but the 3rd bucket seems  
> wrong . Am i missing anything ?
> 
> - 
> - 
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/b725ab85-3fcb-4c3c-a8b1-f3eee20e6718%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/b725ab85-3fcb-4c3c-a8b1-f3eee20e6718%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/b725ab85-3fcb-4c3c-a8b1-f3eee20e6718%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/b725ab85-3fcb-4c3c-a8b1-f3eee20e6718%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
Adrien Grand

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAL6Z4j5jyJbKxTOz5ERR-NwfJzX0w14Y-ttCb9CwgdwFj7awew%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAL6Z4j5jyJbKxTOz5ERR-NwfJzX0w14Y-ttCb9CwgdwFj7awew%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![ananth](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@ananth](https://discuss.elastic.co/u/ananth)\
**Post date:** [December 26, 2014, 9:58am UTC](https://discuss.elastic.co/t/wrong-results-on-terms-aggregations/20774/3 "2014-12-26T09:58:34Z")

</div>

Hi Adrien,

This bug caused due to our application threading issue. Sorry for the wrong  
question.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/e9f56411-47f1-4191-9ea2-470623990d93%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/e9f56411-47f1-4191-9ea2-470623990d93%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:41am UTC](https://discuss.elastic.co/t/wrong-results-on-terms-aggregations/20774/4 "2017-07-06T00:41:55Z")

</div>


