# Cidr plugin - array fields for address input

**URL:** <https://discuss.elastic.co/t/cidr-plugin-array-fields-for-address-input/234270>\
**Category:** Logstash\
**Created:** [May 26, 2020, 8:09am UTC](https://discuss.elastic.co/t/cidr-plugin-array-fields-for-address-input/234270 "2020-05-26T08:09:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mustafa\_Ocak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mustafa_ocak/32/69054_2.png) [@Mustafa\_Ocak](https://discuss.elastic.co/u/Mustafa_Ocak)\
**Post date:** [May 26, 2020, 8:09am UTC](https://discuss.elastic.co/t/cidr-plugin-array-fields-for-address-input/234270/1 "2020-05-26T08:09:15Z")

</div>

Hi,  
I am testing to enrich logs based on host-metadata from filebeat agent (v. 7.7.0).  
Logstash version in this test env. is 7.7.0 and cidr plugin version is 3.1.3.  
Although array field support for address input is added to cidr plugin in v. 3.1.3 as [https://github.com/logstash-plugins/logstash-filter-cidr/issues/19](https://github.com/logstash-plugins/logstash-filter-cidr/issues/19) issue is closed, logstash/cidr still fails with `Invalid IP address, skipping {:address=>"%{[host][ip]}`.

I am aware of using `address => ["%{[host][ip][0]}" , "%{[host][ip][1]}", ... ]` as a workaround but it is messy.

Has anyone experienced this issue and have a solution for this?

Logstash configuration file:

```auto
input { 
  beats {
    port => 5044
    host => "127.0.0.1"
    ssl => false
  }
}
filter {
     cidr {
        add_tag => ["privat-nett"]
        address => ["%{[host][ip]}" ]
        network => ["10.0.2.0/24"]
     }
}
output {
  file {
   path => "/var/log/logstash/test.log"
  }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 26, 2020, 3:52pm UTC](https://discuss.elastic.co/t/cidr-plugin-array-fields-for-address-input/234270/2 "2020-05-26T15:52:29Z")

</div>

The [PR](https://github.com/logstash-plugins/logstash-filter-cidr/commit/04f2a6a89faf88dbdc6d2aaba92af61f38bb77c9) adds support for arrays in the network option, not in the address option. It is unclear to me that issue 19 should have been closed.

---

<div class="post-metadata">

**Author:** ![Mustafa\_Ocak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mustafa_ocak/32/69054_2.png) [@Mustafa\_Ocak](https://discuss.elastic.co/u/Mustafa_Ocak)\
**Post date:** [June 3, 2020, 8:39am UTC](https://discuss.elastic.co/t/cidr-plugin-array-fields-for-address-input/234270/3 "2020-06-03T08:39:38Z")

</div>

Hi,  
According to cidr plugin documentation both network and address field already supports array inputs. This [PR](https://github.com/logstash-plugins/logstash-filter-cidr/commit/04f2a6a89faf88dbdc6d2aaba92af61f38bb77c9) only fixes network field. Apparently, address field cannot handle array input as stated in doc.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 1, 2020, 8:39am UTC](https://discuss.elastic.co/t/cidr-plugin-array-fields-for-address-input/234270/4 "2020-07-01T08:39:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
