# Aggregation on IP arrays

**URL:** <https://discuss.elastic.co/t/aggregation-on-ip-arrays/362851>\
**Category:** Elasticsearch\
**Created:** [July 10, 2024, 8:14am UTC](https://discuss.elastic.co/t/aggregation-on-ip-arrays/362851 "2024-07-10T08:14:23Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![blueren](https://avatars.discourse-cdn.com/v4/letter/b/ecae2f/32.png) [@blueren](https://discuss.elastic.co/u/blueren)\
**Post date:** [July 10, 2024, 8:14am UTC](https://discuss.elastic.co/t/aggregation-on-ip-arrays/362851/1 "2024-07-10T08:14:23Z")

</div>

I have an index with a handful of docs. These docs contain an array "subnets" who's individual elements of of type IP. They contain individual IPs as well as subnets.

Eg\>

```auto
{
 ....,
 ....,
 subnets: ["192.168.0.0/24", "224.0.0.0"]
 ....

```

I'm looking to run something similar to terms aggregation, where in my output contains a concatinated array of all the subnets that the query returns.

The below does not work because we can't run terms aggs on IP field. Is there any alertnative?

```auto
GET networks/_search
{
  "query": {
    "query_string": {
      "query": "networkType: (org or Default)"
    }
  },
  "_source": [
    "subnets"
  ],
  "aggs": {
    "subnets": {
      "terms": {
        "field": "subnets"
      }
    }
  }
}

```

Error:

```auto
root_cause": [
      {
        "type": "illegal_argument_exception",
        "reason": "Field [subnets] of type [ip_range] is not supported for aggregation [terms]"
      }

```

---

<div class="post-metadata">

**Author:** ![Alex\_Salgado-Elastic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_salgado-elastic/32/103081_2.png) [@Alex\_Salgado-Elastic](https://discuss.elastic.co/u/Alex_Salgado-Elastic)\
**Post date:** [July 11, 2024, 9:12pm UTC](https://discuss.elastic.co/t/aggregation-on-ip-arrays/362851/2 "2024-07-11T21:12:06Z")

</div>

Could you try it?

```auto
GET /networks/_search
{
  "query": {
    "query_string": {
      "query": "(org) OR (Default)",
      "default_field": "networkType"
    }
  },
  "_source": [
    "subnets"
  ],
  "aggs": {
    "unique_subnets": {
      "terms": {
        "field": "subnets",
        "size": 100
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![blueren](https://avatars.discourse-cdn.com/v4/letter/b/ecae2f/32.png) [@blueren](https://discuss.elastic.co/u/blueren)\
**Post date:** [July 12, 2024, 6:22am UTC](https://discuss.elastic.co/t/aggregation-on-ip-arrays/362851/3 "2024-07-12T06:22:28Z")

</div>

> [@Alex\_Salgado-Elastic](#):
>
> ```auto
> GET /networks/_search
> {
> "query": {
> "query_string": {
> "query": "(org) OR (Default)",
> "default_field": "networkType"
> }
> },
> "_source": [
> "subnets"
> ],
> "aggs": {
> "unique_subnets": {
> "terms": {
> "field": "subnets",
> "size": 100
> }
> }
> }
> }
> 
> ```

Thanks. But this won't work.

```auto
"root_cause": [
      {
        "type": "illegal_argument_exception",
        "reason": "Field [subnets] of type [ip_range] is not supported for aggregation [terms]"
      }

```

My "subnets" mapping is :

```auto
        "subnets": {
          "type": "ip_range"
        }

```
