# Histogram aggregation on ip addresses

**URL:** <https://discuss.elastic.co/t/histogram-aggregation-on-ip-addresses/79175>\
**Category:** Elasticsearch\
**Created:** [March 19, 2017, 2:53pm UTC](https://discuss.elastic.co/t/histogram-aggregation-on-ip-addresses/79175 "2017-03-19T14:53:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![any\_any\_drop](https://avatars.discourse-cdn.com/v4/letter/a/9f8e36/32.png) [@any\_any\_drop](https://discuss.elastic.co/u/any_any_drop)\
**Post date:** [March 19, 2017, 2:53pm UTC](https://discuss.elastic.co/t/histogram-aggregation-on-ip-addresses/79175/1 "2017-03-19T14:53:42Z")

</div>

Hi there,  
in ES 2 I've been using histogram aggregations to count the number of ip addresses in class c (/24) networks like so:

````auto
    "NETWORKS": {
      "histogram": {
        "field": "ip",
        "interval": 256
      } } }```

Result:
``` {"key_as_string": "10.11.11.0",
          "key": 168495872,
          "doc_count": 5 },
        { "key_as_string": "10.11.12.0",
          "key": 168496128,
          "doc_count": 5 }```

Using ES 5 the aggregation does not work any more:
```"caused_by": {
          "type": "illegal_argument_exception",
          "reason": "Expected numeric type on field [ip], but got [ip]"
        }```

I was thinking about calculating these values using scripts, but they (painless) don't seem to handle ip addresses: [Scripts can't handle IP fields #20067](https://github.com/elastic/elasticsearch/issues/20067).
Another idea was to use [IP Range Aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-iprange-aggregation.html) but it does not work with unknown network ranges.

Does anyone have an idea how to accomplish this in ES 5?

Thanks and cheers,
Markus
````

---

<div class="post-metadata">

**Author:** ![ywelsch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ywelsch/32/7751_2.png) [@ywelsch](https://discuss.elastic.co/u/ywelsch)\
**Post date:** [March 24, 2017, 9:41am UTC](https://discuss.elastic.co/t/histogram-aggregation-on-ip-addresses/79175/2 "2017-03-24T09:41:22Z")

</div>

Scripts on ip addresses should work since ES 5.2.0, see

> <https://github.com/elastic/elasticsearch/pull/22600>

and the example:

[https://github.com/elastic/elasticsearch/blob/master/modules/lang-painless/src/test/resources/rest-api-spec/test/painless/50\_script\_doc\_values.yaml](https://github.com/elastic/elasticsearch/blob/master/modules/lang-painless/src/test/resources/rest-api-spec/test/painless/50_script_doc_values.yaml)

Alternatively you could also categorize the IP address at index time and then use a simple keyword field to store the class c information, and then use a term aggregation on that field to do the count.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 21, 2017, 9:41am UTC](https://discuss.elastic.co/t/histogram-aggregation-on-ip-addresses/79175/3 "2017-04-21T09:41:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
