# Create a watcher to check that the IP address of device is same or changing

**URL:** <https://discuss.elastic.co/t/create-a-watcher-to-check-that-the-ip-address-of-device-is-same-or-changing/305294>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [May 20, 2022, 12:36pm UTC](https://discuss.elastic.co/t/create-a-watcher-to-check-that-the-ip-address-of-device-is-same-or-changing/305294 "2022-05-20T12:36:33Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![no0ne](https://avatars.discourse-cdn.com/v4/letter/n/ac8455/32.png) [@no0ne](https://discuss.elastic.co/u/no0ne)\
**Post date:** [May 20, 2022, 12:36pm UTC](https://discuss.elastic.co/t/create-a-watcher-to-check-that-the-ip-address-of-device-is-same-or-changing/305294/1 "2022-05-20T12:36:33Z")

</div>

I have a data set in which I want to check if each device's IP is the same or changed if it is the same then good if it is changing then notify alert or Jira ticket.

How do I make the watcher for that I am a novice in elastic so that's why I want your little help..

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [May 24, 2022, 6:50pm UTC](https://discuss.elastic.co/t/create-a-watcher-to-check-that-the-ip-address-of-device-is-same-or-changing/305294/2 "2022-05-24T18:50:23Z")

</div>

Are you familiar with Watcher? What you want to do is possible but it will need to be customized to your environment.

In a general sense, I think the easiest way to do this is to run the watch at a regular interval (for example, once per day) and then for each device, count the number of distinct IP addresses. And if that device has more than 1 IP, then clearly it's changed.

So for example, here's the query part of the Watch:

```auto
          "body": {
            "size": 0,
            "query": {
              "bool": {
                "filter": [
                  {
                    "range": {
                      "@timestamp": {
                        "gte": "now-1d/d",
                        "lte": "now"
                      }
                    }
                  }
                ]
              }
            },
            "aggs": {
              "devices": {
                "terms": {
                  "field": "devicename",
                  "size": 10000
                },
                "aggs": {
                  "distinct_ips": {
                    "cardinality": {
                      "field": "ip"
                    }
                  },
                  "ips": {
                    "terms": {
                      "field": "ip",
                      "size": 10000
                    }
                  }
                }
              }
            }
          }

```

And in the condition part, you could do something like:

```auto
    "condition": {
      "script": """
        return ctx.payload.aggregations.devices.buckets.stream().anyMatch(b -> b.distinct_ips.value > 1);
          """
    },

```

As for the `actions` section, you will need a `transform` section to filter and flatten the results. Something like:

```auto
        "transform": {
          "script": """
         return ctx.payload.aggregations.devices.buckets.stream().filter(b -> b.distinct_ips.value > 1).flatMap(b -> b.ips.buckets.stream().map(innerB -> ['ip':innerB.key,'device':b.key])).collect(Collectors.toList());
          """
        },

```

And when you actually alert you can iterate thought the output with something similar to:

```auto
         {{#ctx.payload._value}}
          device:{{device}} has {{ip}}
        {{/ctx.payload._value}}

```

to produce an output that looks like:

```auto
          device:foo has 168.72.100.1
          device:foo has 168.72.100.17

```

Full example [here](https://gist.github.com/richcollier/1277871cfd3c746c55361ff0f38f2b00)

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [May 25, 2022, 6:24pm UTC](https://discuss.elastic.co/t/create-a-watcher-to-check-that-the-ip-address-of-device-is-same-or-changing/305294/4 "2022-05-25T18:24:04Z")

</div>

The `size` specifies a maximum number of devices/IPs to aggregate on.

> how can I check all devices with changing Ip in one day or in a single run?

This example, as constructed, will do that. It's just that the example data I used only had one instance of a device with a changing IP.

---

<div class="post-metadata">

**Author:** ![no0ne](https://avatars.discourse-cdn.com/v4/letter/n/ac8455/32.png) [@no0ne](https://discuss.elastic.co/u/no0ne)\
**Post date:** [May 26, 2022, 3:19pm UTC](https://discuss.elastic.co/t/create-a-watcher-to-check-that-the-ip-address-of-device-is-same-or-changing/305294/5 "2022-05-26T15:19:35Z")

</div>

Thanks boss, that solution perfectly worked

---

<div class="post-metadata">

**Author:** ![no0ne](https://avatars.discourse-cdn.com/v4/letter/n/ac8455/32.png) [@no0ne](https://discuss.elastic.co/u/no0ne)\
**Post date:** [May 27, 2022, 6:11pm UTC](https://discuss.elastic.co/t/create-a-watcher-to-check-that-the-ip-address-of-device-is-same-or-changing/305294/6 "2022-05-27T18:11:23Z")

</div>

In this logic how we can trigger action in case of distinct is greater than 1 and the IPs in that object have any un-matched element in first 3 number of IP  
e.g:  
192.10.0.1  
182.10.1.0

so in above case trigger action,

That should be the logic 🙂

```auto
List<String> strings = Arrays.asList("193.168.10.0", "192.168.10.1", "192.168.10.2");
        System.out.println(strings.stream().allMatch(string ->
                strings.get(0).substring(0, 10).equals(string.substring(0, 10))));

```

In-case if IP has 255.192.100.1 the above logic won't work, means hard-coded value won't work.  
so updated logic is like.

```auto
 String substringToBeMatched = strings.get(0).substring(0, strings.get(0).lastIndexOf(".")) ;
        System.out.println(strings.stream().allMatch(string ->
                substringToBeMatched
                        .equals(string.substring(0, string.lastIndexOf(".")))));

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 24, 2022, 6:11pm UTC](https://discuss.elastic.co/t/create-a-watcher-to-check-that-the-ip-address-of-device-is-same-or-changing/305294/7 "2022-06-24T18:11:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
