# Cidr plugin just generate warnings

**URL:** <https://discuss.elastic.co/t/cidr-plugin-just-generate-warnings/141776>\
**Category:** Logstash\
**Created:** [July 26, 2018, 1:15pm UTC](https://discuss.elastic.co/t/cidr-plugin-just-generate-warnings/141776 "2018-07-26T13:15:49Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![maxf](https://avatars.discourse-cdn.com/v4/letter/m/779978/32.png) [@maxf](https://discuss.elastic.co/u/maxf)\
**Post date:** [July 26, 2018, 1:15pm UTC](https://discuss.elastic.co/t/cidr-plugin-just-generate-warnings/141776/1 "2018-07-26T13:15:49Z")

</div>

Hello. I've got a trouble with cidr plugin. Im trying to use it this way:

> if ([maliciousIP] == 'false' and [target\_host]=~ /^([0-9]{1,3}.){3}([0-9]{1,3})/)  
> {   
> cidr  
> {  
> address =\> ["%{target\_host}"]  
> network\_path =\> '/etc/logstash/conf.d/ipblacklists/subnets.yaml'  
> add\_field =\> { "DangerousSubnet" =\> "true" }  
> }  
> }

but i only got

> [WARN][logstash.filters.cidr] Invalid IP address, skipping {:address=\>"%{target\_host}"

in my logs and field DangerousSubnet not added.  
Whats wrong?

---

<div class="post-metadata">

**Author:** ![maxf](https://avatars.discourse-cdn.com/v4/letter/m/779978/32.png) [@maxf](https://discuss.elastic.co/u/maxf)\
**Post date:** [August 6, 2018, 5:53am UTC](https://discuss.elastic.co/t/cidr-plugin-just-generate-warnings/141776/2 "2018-08-06T05:53:23Z")

</div>

the question is still relevant

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 6, 2018, 3:58pm UTC](https://discuss.elastic.co/t/cidr-plugin-just-generate-warnings/141776/3 "2018-08-06T15:58:30Z")

</div>

this question is not an `Elasticsearch` question, so I moved it over to the `Logstash` forum. Hopefully you will get an answer there.

Have you verified the field content of that address? What is it?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 6, 2018, 5:09pm UTC](https://discuss.elastic.co/t/cidr-plugin-just-generate-warnings/141776/4 "2018-08-06T17:09:06Z")

</div>

The field was not added because the filter did not successfuly complete. Decoration only happens when a filter succeeds.

The message you are getting suggests the field does not exist, so the field substitution does not occur. How that condition could test true if the field does not exist is beyond me.

---

<div class="post-metadata">

**Author:** ![maxf](https://avatars.discourse-cdn.com/v4/letter/m/779978/32.png) [@maxf](https://discuss.elastic.co/u/maxf)\
**Post date:** [August 13, 2018, 9:23am UTC](https://discuss.elastic.co/t/cidr-plugin-just-generate-warnings/141776/5 "2018-08-13T09:23:29Z")

</div>

Content is ip addresses from dns logs. Like '23.100.122.175' etc.  
Field added in config before

---

<div class="post-metadata">

**Author:** ![maxf](https://avatars.discourse-cdn.com/v4/letter/m/779978/32.png) [@maxf](https://discuss.elastic.co/u/maxf)\
**Post date:** [August 13, 2018, 10:22am UTC](https://discuss.elastic.co/t/cidr-plugin-just-generate-warnings/141776/6 "2018-08-13T10:22:15Z")

</div>

Oh. Sorry, im blind. I incorrectly used the dns plugin, and therefore I do not have an address in this field.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 10, 2018, 10:22am UTC](https://discuss.elastic.co/t/cidr-plugin-just-generate-warnings/141776/7 "2018-09-10T10:22:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
