# Error when using elasticsearch logstash filter

**URL:** <https://discuss.elastic.co/t/error-when-using-elasticsearch-logstash-filter/301952>\
**Category:** Logstash\
**Created:** [April 8, 2022, 10:24am UTC](https://discuss.elastic.co/t/error-when-using-elasticsearch-logstash-filter/301952 "2022-04-08T10:24:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vladislav](https://avatars.discourse-cdn.com/v4/letter/v/bbce88/32.png) [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Post date:** [April 8, 2022, 10:24am UTC](https://discuss.elastic.co/t/error-when-using-elasticsearch-logstash-filter/301952/1 "2022-04-08T10:24:22Z")

</div>

Good day! Please advice.  
I have an error when using Elasticsearch logstash filter. I need to make a query among index to find a value of ip, and if there is write it in the field 'match'  
Here is code of my .conf file:

```auto
input {
    udp {
        port => 5555
    }
}
filter {
    if [direction] == "outgoing" {
      elasticsearch {
        hosts => ["elasticsearch:9200"]
        index => "filebeat-1"
        query => "_exists_:threatintel.indicator.ip AND threatintel.indicator.ip:%{[dst]}"
        fields => { "threatintel.indicator.ip" => "match" }
	  }
	}
}
output {
    elasticsearch {
        hosts => ["elasticsearch:9200"]
        index => "logstash-1"
    }
}

```

An error occurs while executing:  
`Failed to query elasticsearch for previous event {:index=>"filebeat-1", :error=>"[400] {\"error\":{\"root_cause\":[{\"type\":\"query_shard_exception\",\"reason\":\"failed to create query: '%' is not an IP string literal.\",\"index_uuid\":\"1f6v8pEtQDKocMesc02LrQ\",\"index\":\"filebeat-1\"}],\"type\":\"search_phase_execution_exception\",\"reason\":\"all shards failed\",\"phase\":\"query\",\"grouped\":true,\"failed_shards\":[{\"shard\":0,\"index\":\"filebeat-1\",\"node\":\"HsYTd-D5QRyX4tn2VaQs8A\"`

It should be noted that the field threatintel.indicator.ip has an 'ip address field' type and dst field is string. Could this be the cause of the problem? Or is there another reason?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 8, 2022, 2:29pm UTC](https://discuss.elastic.co/t/error-when-using-elasticsearch-logstash-filter/301952/2 "2022-04-08T14:29:32Z")

</div>

> [@vladislav](#):
>
> Failed to query elasticsearch for previous event {:index=\>"filebeat-1", :error=\>"[400] {"error":{"root\_cause":[{"type":"query\_shard\_exception","reason":"failed to create query: '%' is not an IP string

elasticsearch is returning that error. The only way elasticsearch will see the % is if the [dst] field does not exist on an event, in which case %{[dst]} will not get substituted when the filter calls sprintf.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 6, 2022, 2:30pm UTC](https://discuss.elastic.co/t/error-when-using-elasticsearch-logstash-filter/301952/3 "2022-05-06T14:30:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
