# Best way to enrich by IP subnets

**URL:** <https://discuss.elastic.co/t/best-way-to-enrich-by-ip-subnets/232771>\
**Category:** Elasticsearch\
**Created:** [May 15, 2020, 8:40am UTC](https://discuss.elastic.co/t/best-way-to-enrich-by-ip-subnets/232771 "2020-05-15T08:40:26Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![nemhods](https://avatars.discourse-cdn.com/v4/letter/n/48db29/32.png) [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Post date:** [May 15, 2020, 8:40am UTC](https://discuss.elastic.co/t/best-way-to-enrich-by-ip-subnets/232771/1 "2020-05-15T08:40:26Z")

</div>

I want to enrich incoming ECS-compatible documents with a tag if they come from VPN IPs.

From my testing, the enrich processor cannot deal with IP-ranges. However, i want to use IP-ranges and not manually (or by a script) spell out thousands of IPs for the enrich policy. What's the best strategy to achieve this?

> **Summary**
>
> PUT test-ip-range-lookup  
> {  
> "settings": {  
> "number\_of\_shards": 1  
> },  
> "mappings": {  
> "properties": {  
> "ip": {  
> "type": "ip\_range"  
> }  
> }  
> }  
> }
> 
> POST test-ip-range-lookup/\_doc/vpn-ips  
> {  
> "ip": "192.168.0.0/16",  
> "tags": ["vpn-ip"]  
> }
> 
> PUT \_enrich/policy/test-ip-enrich  
> {  
> "match": {  
> "indices": "test-ip-lookup",  
> "match\_field": "ip",  
> "enrich\_fields": ["tags"]  
> }  
> }
> 
> POST \_enrich/policy/test-ip-enrich/\_execute
> 
> POST \_ingest/pipeline/\_simulate  
> {  
> "docs": [  
> {  
> "\_source": {  
> "host": {  
> "ip": "192.168.0.1"  
> }  
> }  
> }  
> ],  
> "pipeline": {  
> "processors": [  
> {  
> "enrich": {  
> "policy\_name": "test-ip-enrich",  
> "field": "host.ip",  
> "target\_field": "tags",  
> "ignore\_missing": true  
> }  
> }  
> ]  
> }  
> }

---

<div class="post-metadata">

**Author:** ![whatgeorgemade](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/whatgeorgemade/32/103246_2.png) [@whatgeorgemade](https://discuss.elastic.co/u/whatgeorgemade)\
**Post date:** [May 15, 2020, 6:42pm UTC](https://discuss.elastic.co/t/best-way-to-enrich-by-ip-subnets/232771/2 "2020-05-15T18:42:43Z")

</div>

You're correct about the enrich processor. Support for range queries has been requested, among other features.

What's sending the documents to the cluster?

If it's something you've built yourself, implement the enrichment query and add to the document before indexing it.

If you can't change the code, set the output to logstash and implement a pipeline with an Elasticsearch filter to do the enrichment.

---

<div class="post-metadata">

**Author:** ![nemhods](https://avatars.discourse-cdn.com/v4/letter/n/48db29/32.png) [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Post date:** [May 18, 2020, 6:23am UTC](https://discuss.elastic.co/t/best-way-to-enrich-by-ip-subnets/232771/3 "2020-05-18T06:23:59Z")

</div>

Ah thanks, thats a good idea I hadn't thought of before.

I think I'd rather wait for the enrich processor to support other datatypes though. Since I'm only using the vpn-tag for one watcher use-case, I'll just use the terms query for now (it supports searching for CIDR-strings against IP fields)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 15, 2020, 6:24am UTC](https://discuss.elastic.co/t/best-way-to-enrich-by-ip-subnets/232771/4 "2020-06-15T06:24:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![Michael\_Bischoff](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_bischoff/32/98672_2.png) [@Michael\_Bischoff](https://discuss.elastic.co/u/Michael_Bischoff)\
**Post date:** [December 10, 2021, 9:34am UTC](https://discuss.elastic.co/t/best-way-to-enrich-by-ip-subnets/232771/5 "2021-12-10T09:34:40Z")

</div>

Just wanted to let you know that Elasticsearch 7.16 was released with this functionality, see [Example: Enrich your data by matching a value to a range | Elasticsearch Guide [7.16] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.16/range-enrich-policy-type.html) for an example. Thank you for your feedback.
