# CIDR,subnet relating

**URL:** <https://discuss.elastic.co/t/cidr-subnet-relating/76757>\
**Category:** Logstash\
**Created:** [February 28, 2017, 10:09am UTC](https://discuss.elastic.co/t/cidr-subnet-relating/76757 "2017-02-28T10:09:12Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [February 28, 2017, 10:09am UTC](https://discuss.elastic.co/t/cidr-subnet-relating/76757/1 "2017-02-28T10:09:12Z")

</div>

Hi All,

Will I be able to match my ip address to subnets ,i know we can use CIDR ,but I have around 800 subnets is there any way I can match the ip addresses with that using translate and CIDR together .

I want to match my source ip and destination ip , to the csv file which I have for 800 subnets with location details.

Any help would be appreciable and useful for me

Thank you in Advance

Raj

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [March 1, 2017, 12:49pm UTC](https://discuss.elastic.co/t/cidr-subnet-relating/76757/2 "2017-03-01T12:49:44Z")

</div>

Any help pls 🙂

---

<div class="post-metadata">

**Author:** ![bertvervaele](https://avatars.discourse-cdn.com/v4/letter/b/8e7dd6/32.png) [@bertvervaele](https://discuss.elastic.co/u/bertvervaele)\
**Post date:** [March 1, 2017, 1:32pm UTC](https://discuss.elastic.co/t/cidr-subnet-relating/76757/3 "2017-03-01T13:32:42Z")

</div>

I'm pretty sure you can do this very easy.  
lets's say you have a subnet 192.168.0.0-192.168.0.255 called Home.  
You should have a field IPSource that reads the ip from the message.  
then use an if in your output:

if "192.168.0.\*" in [IPSource]{  
subnet =\> "Home"  
}

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [March 1, 2017, 1:37pm UTC](https://discuss.elastic.co/t/cidr-subnet-relating/76757/4 "2017-03-01T13:37:04Z")

</div>

Thank you so much for the reply ,but i have 800 unique subnets with different location names, is it only way to hard code each every subnets?

---

<div class="post-metadata">

**Author:** ![bertvervaele](https://avatars.discourse-cdn.com/v4/letter/b/8e7dd6/32.png) [@bertvervaele](https://discuss.elastic.co/u/bertvervaele)\
**Post date:** [March 1, 2017, 1:39pm UTC](https://discuss.elastic.co/t/cidr-subnet-relating/76757/5 "2017-03-01T13:39:12Z")

</div>

If I were you I would just read both files in and then match them in elasticsearch. I think elasticsearch is beter fit to solve this problem.

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [March 1, 2017, 1:59pm UTC](https://discuss.elastic.co/t/cidr-subnet-relating/76757/6 "2017-03-01T13:59:33Z")

</div>

77.72.127.96/29 25 home  
67.72.107.88/29 25 home2  
52.211.247.96/27 home3   
47.72.84.0/27 home4  
31.161.152.0/24 home5  
27.73.110.0/23 home6

Something like this if i get a source ip in 77.72.127.97 in my logs, i should get a field name called home

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [March 1, 2017, 2:08pm UTC](https://discuss.elastic.co/t/cidr-subnet-relating/76757/7 "2017-03-01T14:08:29Z")

</div>

Any sugesstions ? 🙂

---

<div class="post-metadata">

**Author:** ![bertvervaele](https://avatars.discourse-cdn.com/v4/letter/b/8e7dd6/32.png) [@bertvervaele](https://discuss.elastic.co/u/bertvervaele)\
**Post date:** [March 1, 2017, 2:09pm UTC](https://discuss.elastic.co/t/cidr-subnet-relating/76757/8 "2017-03-01T14:09:40Z")

</div>

I'm also a beginner I just started using ELK since 1 week so I can't just give you the answer but I can help looking 🙂

[https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-iprange-aggregation.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-iprange-aggregation.html)

This looks pretty usefull. Just take your time and look some more into elasticsearch I'm pretty sure you can find the solution in less then a day 🙂

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [March 1, 2017, 2:11pm UTC](https://discuss.elastic.co/t/cidr-subnet-relating/76757/9 "2017-03-01T14:11:21Z")

</div>

Thank you 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2017, 2:11pm UTC](https://discuss.elastic.co/t/cidr-subnet-relating/76757/10 "2017-03-29T14:11:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
