# Finding ip address ranges that contain a given ip address

**URL:** <https://discuss.elastic.co/t/finding-ip-address-ranges-that-contain-a-given-ip-address/9719>\
**Category:** Elasticsearch\
**Created:** [November 14, 2012, 6:51pm UTC](https://discuss.elastic.co/t/finding-ip-address-ranges-that-contain-a-given-ip-address/9719 "2012-11-14T18:51:32Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sylvain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sylvain/32/2476_2.png) [@sylvain](https://discuss.elastic.co/u/sylvain)\
**Post date:** [November 14, 2012, 6:51pm UTC](https://discuss.elastic.co/t/finding-ip-address-ranges-that-contain-a-given-ip-address/9719/1 "2012-11-14T18:51:32Z")

</div>

Hi,

assuming documents that have an object type defining an ip address range,  
what would be the recommended way to retrieve documents for which the ip  
range(s) contain a given ip address.

_mapping:_  
'ip\_doc': {  
'properties': {  
'ip\_range' : {  
'type': 'object',  
'properties': {  
'from': {'type': 'ip'},  
'to': {'type': 'ip'}  
}  
}  
}  
}

_sample documents:_  
doc1 = {'ip\_doc': {'ip\_ranges' : {'from': '1.0.0.0', 'to': '2.255.255.255'  
}}}  
doc2 = {'ip\_doc': {'ip\_ranges' : {'from': '2.0.0.0', 'to': '2.255.255.255'  
}}}  
doc3 = {'ip\_doc': {'ip\_ranges' : {'from': '3.0.0.0', 'to': '3.255.255.255'  
}}}

So for ip = '2.0.0.0', doc1 and doc2 should be retrieved.

Thanks,  
Sylvain

--

---

<div class="post-metadata">

**Author:** ![Clinton\_Gormley](https://avatars.discourse-cdn.com/v4/letter/c/50afbb/32.png) [@Clinton\_Gormley](https://discuss.elastic.co/u/Clinton_Gormley)\
**Post date:** [November 14, 2012, 7:13pm UTC](https://discuss.elastic.co/t/finding-ip-address-ranges-that-contain-a-given-ip-address/9719/2 "2012-11-14T19:13:08Z")

</div>

Hi Sylvain

> assuming documents that have an object type defining an ip address  
> range, what would be the recommended way to retrieve documents for  
> which the ip range(s) contain a given ip address.

> doc1 = {'ip\_doc': {'ip\_ranges' : {'from': '1.0.0.0', 'to':  
> '2.255.255.255'}}}  
> doc2 = {'ip\_doc': {'ip\_ranges' : {'from': '2.0.0.0', 'to':  
> '2.255.255.255'}}}  
> doc3 = {'ip\_doc': {'ip\_ranges' : {'from': '3.0.0.0', 'to':  
> '3.255.255.255'}}}
> 
> So for ip = '2.0.0.0', doc1 and doc2 should be retrieved.

This will work:  
curl -XGET '[http://127.0.0.1:9200/test/ip\_doc/\_search?pretty=1](http://127.0.0.1:9200/test/ip_doc/_search?pretty=1)' -d '  
{  
"query" : {  
"constant\_score" : {  
"filter" : {  
"and" : [  
{  
"range" : {  
"ip\_range.to" : {  
"gte" : "2.0.0.0"  
}  
}  
},  
{  
"range" : {  
"ip\_range.from" : {  
"lte" : "2.0.0.0"  
}  
}  
}  
]  
}  
}  
}  
}  
'

One thing - you map your field as "ip\_range" then you index your docs as  
"ip\_ranges" (with an "s"). I'm assuming that was an error and you you  
only have a single ip\_range per doc. If you have multiple ip\_ranges,  
then you will need to change the mapping from type "object" to type  
"nested" and use a nested filter instead.

clint

--

---

<div class="post-metadata">

**Author:** ![sylvain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sylvain/32/2476_2.png) [@sylvain](https://discuss.elastic.co/u/sylvain)\
**Post date:** [November 15, 2012, 3:06pm UTC](https://discuss.elastic.co/t/finding-ip-address-ranges-that-contain-a-given-ip-address/9719/3 "2012-11-15T15:06:13Z")

</div>

Hi Clint,

thanks for the help! We actually may have multiple ip ranges, so your tip  
about using the nested type & filter is appreciated! I tried it and it  
works, so thanks again.

Best regards,  
Sylvain

On Wednesday, November 14, 2012 8:13:24 PM UTC+1, Clinton Gormley wrote:

> Hi Sylvain
> 
> > assuming documents that have an object type defining an ip address  
> > range, what would be the recommended way to retrieve documents for  
> > which the ip range(s) contain a given ip address.
> 
> > doc1 = {'ip\_doc': {'ip\_ranges' : {'from': '1.0.0.0', 'to':  
> > '2.255.255.255'}}}  
> > doc2 = {'ip\_doc': {'ip\_ranges' : {'from': '2.0.0.0', 'to':  
> > '2.255.255.255'}}}  
> > doc3 = {'ip\_doc': {'ip\_ranges' : {'from': '3.0.0.0', 'to':  
> > '3.255.255.255'}}}
> > 
> > So for ip = '2.0.0.0', doc1 and doc2 should be retrieved.
> 
> This will work:  
> curl -XGET '[http://127.0.0.1:9200/test/ip\_doc/\_search?pretty=1](http://127.0.0.1:9200/test/ip_doc/_search?pretty=1)' -d '  
> {  
> "query" : {  
> "constant\_score" : {  
> "filter" : {  
> "and" : [  
> {  
> "range" : {  
> "ip\_range.to" : {  
> "gte" : "2.0.0.0"  
> }  
> }  
> },  
> {  
> "range" : {  
> "ip\_range.from" : {  
> "lte" : "2.0.0.0"  
> }  
> }  
> }  
> ]  
> }  
> }  
> }  
> }  
> '
> 
> One thing - you map your field as "ip\_range" then you index your docs as  
> "ip\_ranges" (with an "s"). I'm assuming that was an error and you you  
> only have a single ip\_range per doc. If you have multiple ip\_ranges,  
> then you will need to change the mapping from type "object" to type  
> "nested" and use a nested filter instead.
> 
> clint

--

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 3:04am UTC](https://discuss.elastic.co/t/finding-ip-address-ranges-that-contain-a-given-ip-address/9719/4 "2017-07-06T03:04:07Z")

</div>


