# How to convert ip long to string, to get ip subnets aggs

**URL:** <https://discuss.elastic.co/t/how-to-convert-ip-long-to-string-to-get-ip-subnets-aggs/27097>\
**Category:** Elasticsearch\
**Created:** [August 10, 2015, 4:48am UTC](https://discuss.elastic.co/t/how-to-convert-ip-long-to-string-to-get-ip-subnets-aggs/27097 "2015-08-10T04:48:16Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![LubyRuffy](https://avatars.discourse-cdn.com/v4/letter/l/9de0a6/32.png) [@LubyRuffy](https://discuss.elastic.co/u/LubyRuffy)\
**Post date:** [August 10, 2015, 4:48am UTC](https://discuss.elastic.co/t/how-to-convert-ip-long-to-string-to-get-ip-subnets-aggs/27097/1 "2015-08-10T04:48:16Z")

</div>

there is a field named ip, which mapped to ip type, now i want to aggs as /24 subnets, i use script "doc['ip'].value & 0xffffff00" to get long value of ip, how to next to convert it to ip string???

```
{
  "_source": [
    "host",
    "ip"
  ],
  "aggs": {
    "ip_subnet": {
      "terms": {
        "script": "doc['ip'].value & 0xffffff00"
      }
    }
  },
  "size": 0
}

```

I didn't found any result from elastic website, I wonder know if there is another way to receive the subnets aggs?

I also tried doc['ipstr'].value.split('.')[0..2].join('.') but also not work.

Thank you very much, and forgive my pool english 😉

---

<div class="post-metadata">

**Author:** ![LubyRuffy](https://avatars.discourse-cdn.com/v4/letter/l/9de0a6/32.png) [@LubyRuffy](https://discuss.elastic.co/u/LubyRuffy)\
**Post date:** [August 10, 2015, 4:01pm UTC](https://discuss.elastic.co/t/how-to-convert-ip-long-to-string-to-get-ip-subnets-aggs/27097/2 "2015-08-10T16:01:34Z")

</div>

anybody help?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [August 10, 2015, 4:20pm UTC](https://discuss.elastic.co/t/how-to-convert-ip-long-to-string-to-get-ip-subnets-aggs/27097/3 "2015-08-10T16:20:37Z")

</div>

Why would you want to change it to a string? You should be able to do [bucket aggregations on ip type](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-iprange-aggregation.html).

---

<div class="post-metadata">

**Author:** ![LubyRuffy](https://avatars.discourse-cdn.com/v4/letter/l/9de0a6/32.png) [@LubyRuffy](https://discuss.elastic.co/u/LubyRuffy)\
**Post date:** [August 10, 2015, 5:27pm UTC](https://discuss.elastic.co/t/how-to-convert-ip-long-to-string-to-get-ip-subnets-aggs/27097/4 "2015-08-10T17:27:31Z")

</div>

thank u for reply.

I want to group by ip's subnet, not just ip. and ip range it's not suite cause i don't know the range, just wanna group by all subnet.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [August 10, 2015, 5:44pm UTC](https://discuss.elastic.co/t/how-to-convert-ip-long-to-string-to-get-ip-subnets-aggs/27097/5 "2015-08-10T17:44:26Z")

</div>

But you can group by subnet, as [defined in the document I linked previously](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-iprange-aggregation.html). Note the CIDR netmask/subnet filter in this example:

> IP ranges can also be defined as CIDR masks:

> ```
> {
> "aggs" : {
> "ip_ranges" : {
> "ip_range" : {
> "field" : "ip",
> "ranges" : [
> { "mask" : "10.0.0.0/25" },
> { "mask" : "10.0.0.127/25" }
> ]
> }
> }
> }
> }
> 
> ```

> Response:

> ```
> {
> "aggregations": {
> "ip_ranges": {
> "buckets": [
> {
> "key": "10.0.0.0/25",
> "from": 1.6777216E+8,
> "from_as_string": "10.0.0.0",
> "to": 167772287,
> "to_as_string": "10.0.0.127",
> "doc_count": 127
> },
> {
> "key": "10.0.0.127/25",
> "from": 1.6777216E+8,
> "from_as_string": "10.0.0.0",
> "to": 167772287,
> "to_as_string": "10.0.0.127",
> "doc_count": 127
> }
> ]
> }
> }
> }
> 
> ```

---

<div class="post-metadata">

**Author:** ![LubyRuffy](https://avatars.discourse-cdn.com/v4/letter/l/9de0a6/32.png) [@LubyRuffy](https://discuss.elastic.co/u/LubyRuffy)\
**Post date:** [August 10, 2015, 5:45pm UTC](https://discuss.elastic.co/t/how-to-convert-ip-long-to-string-to-get-ip-subnets-aggs/27097/6 "2015-08-10T17:45:24Z")

</div>

i mean i don't know which subnet it has, these could be any ip range...

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [August 10, 2015, 5:48pm UTC](https://discuss.elastic.co/t/how-to-convert-ip-long-to-string-to-get-ip-subnets-aggs/27097/7 "2015-08-10T17:48:07Z")

</div>

I'm not sure in that case, but I don't think there's anything built-in that will do that for you (at least not one that's accessible). You might find something and script it out, as there are converters back and forth on that count.

---

<div class="post-metadata">

**Author:** ![LubyRuffy](https://avatars.discourse-cdn.com/v4/letter/l/9de0a6/32.png) [@LubyRuffy](https://discuss.elastic.co/u/LubyRuffy)\
**Post date:** [August 10, 2015, 5:53pm UTC](https://discuss.elastic.co/t/how-to-convert-ip-long-to-string-to-get-ip-subnets-aggs/27097/8 "2015-08-10T17:53:12Z")

</div>

Tks :0  
I found a blog here : [http://chenlinux.com/2014/11/27/elasticsearch-scripts-aggregations/](http://chenlinux.com/2014/11/27/elasticsearch-scripts-aggregations/)  
He did what i want, I tried but not work...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:56pm UTC](https://discuss.elastic.co/t/how-to-convert-ip-long-to-string-to-get-ip-subnets-aggs/27097/9 "2017-07-05T23:56:34Z")

</div>


