# Grok pattern for IPv6 not working with %{IPORHOST} - Azure Logs - Filebeat 7.14.1

**URL:** <https://discuss.elastic.co/t/grok-pattern-for-ipv6-not-working-with-iporhost-azure-logs-filebeat-7-14-1/285699>\
**Category:** Beats\
**Tags:** filebeat, ingest-pipeline\
**Created:** [October 1, 2021, 5:09pm UTC](https://discuss.elastic.co/t/grok-pattern-for-ipv6-not-working-with-iporhost-azure-logs-filebeat-7-14-1/285699 "2021-10-01T17:09:11Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![smandolare](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/smandolare/32/95346_2.png) [@smandolare](https://discuss.elastic.co/u/smandolare)\
**Post date:** [October 1, 2021, 5:09pm UTC](https://discuss.elastic.co/t/grok-pattern-for-ipv6-not-working-with-iporhost-azure-logs-filebeat-7-14-1/285699/1 "2021-10-01T17:09:11Z")

</div>

Elasticsearch is failing to index events with a 400 error attempting to parse an IPv6 event in the Azure Platform Pipeline:

```auto
"status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [source.ip] of type [ip] in document with id ''. Preview of field's value: '2405'", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"'2405' is not an IP string literal."}}}}}

```

This issue is similar to or also records at:  
[https://issueexplorer.com/issue/elastic/beats/28068](https://issueexplorer.com/issue/elastic/beats/28068)

> <https://github.com/influxdata/telegraf/issues/1973>
>
> The default %{COMBINED\_LOG\_FORMAT} can't understand even simple IPv6 addresses:
> …\`2001:0db8:85a3:0000:0000:8a2e:0370:7334\` with \`%{IPORHOST}\` becomes: \`"IPORHOST": \["2001" \]\`
> 
> But if we use the definition from \[Logstash's patters\](https://github.com/logstash-plugins/logstash-patterns-core/blob/master/patterns/grok-patterns) \`IPORHOST (?:%{IP}|%{HOSTNAME})\` it can match the whole IPv6 address.
> 
> Furthermore with the definition above it still can't match IPv4-compatible addresses, like \`::ffff:192.0.2.128\`, but that can be solved by replacing "listen \[::\]:80 ipv6only=off;" with "listen 80; listen \[::\]:80 ipv6only=on;" at nginx's server config.
> 
> Telegraf - version 1.0.1

Testing an IPv6 Address against this pattern using [https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/) returns the same result, the first hex block of the IPv6 is returned as the hostname.

To workaround the issue specifically with the Azure ingest pipeline %{IPV6} was added as a first check sequence but the Grok pattern IPORHOST will need attention.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 29, 2021, 7:09pm UTC](https://discuss.elastic.co/t/grok-pattern-for-ipv6-not-working-with-iporhost-azure-logs-filebeat-7-14-1/285699/2 "2021-10-29T19:09:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
