# CIDR filter reports IP6 addresses as invalid

**URL:** <https://discuss.elastic.co/t/cidr-filter-reports-ip6-addresses-as-invalid/198959>\
**Category:** Logstash\
**Created:** [September 10, 2019, 6:51pm UTC](https://discuss.elastic.co/t/cidr-filter-reports-ip6-addresses-as-invalid/198959 "2019-09-10T18:51:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![daniel.dayley](https://avatars.discourse-cdn.com/v4/letter/d/e9bcb4/32.png) [@daniel.dayley](https://discuss.elastic.co/u/daniel.dayley)\
**Post date:** [September 10, 2019, 6:51pm UTC](https://discuss.elastic.co/t/cidr-filter-reports-ip6-addresses-as-invalid/198959/1 "2019-09-10T18:51:29Z")

</div>

Hey guys, I'm hoping this is an issue on my end rather than an issue with the CIDR filter, but I'm seeing a lot of logstash errors in my CIDR filter relating to certain IP addresses:

```
[WARN][logstash.filters.cidr] Invalid IP address, skipping {:address=>"%{src}", :event=>#<LogStash::Event:0x54e98d7f>}

```

My current code relating to that portion is:

```
cidr {
           address => ["%{src}"]
           network_path => "/etc/tables/networks"
           add_field => { "source.internal" => true }
}
mutate {convert => {"source.internal" => "boolean"}}

```

All the addresses that are triggering the warning are IP6 addresses such as:

```
2001:2:0:aab1:d94a:844b:7604:ddde
2620:12b:d000:400::1fc5

```

I'm showing those IP addresses as valid, is there something I'm missing?  
Thanks!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 10, 2019, 7:15pm UTC](https://discuss.elastic.co/t/cidr-filter-reports-ip6-addresses-as-invalid/198959/2 "2019-09-10T19:15:56Z")

</div>

This works for me.

```
input { generator { count => 1 lines => [''] } }
filter {
    mutate { add_field => { "src" => "2001:2:0:aab1:d94a:844b:7604:ddde" } }
    cidr { address => "%{src}" add_field => { "source.internal" => true } network => "2001:2:0::/48" }
}
output { stdout { codec => rubydebug { metadata => false } } }

```

Are you sure that is the value of your [src] field? Leading or trailing blanks would cause that failure.

It would have been nice if the filter logged the address after it has been sprintf'd.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 8, 2019, 7:15pm UTC](https://discuss.elastic.co/t/cidr-filter-reports-ip6-addresses-as-invalid/198959/3 "2019-10-08T19:15:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
