# How to fetch only Public or Private IP in ES?

**URL:** <https://discuss.elastic.co/t/how-to-fetch-only-public-or-private-ip-in-es/248717>\
**Category:** Elasticsearch\
**Created:** [September 15, 2020, 5:41pm UTC](https://discuss.elastic.co/t/how-to-fetch-only-public-or-private-ip-in-es/248717 "2020-09-15T17:41:49Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ramesh\_balasubramani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramesh_balasubramani/32/53173_2.png) [@Ramesh\_balasubramani](https://discuss.elastic.co/u/Ramesh_balasubramani)\
**Post date:** [September 15, 2020, 5:41pm UTC](https://discuss.elastic.co/t/how-to-fetch-only-public-or-private-ip-in-es/248717/1 "2020-09-15T17:41:49Z")

</div>

```
GET logstash-ramesh-2020.09.16/_search
{
   "query": {
  "bool": {
      "must_not": [
         {
             "regexp": {
                "src_ip.raw": {
                   "value": "^(?:10|127|172\\.(?:1[6-9]|2[0-9]|3[01])|192\\.168)\\..*"
                }
             }
         }
      ]
  }
   },
   "_source": [
  "src_ip"
   ]
}

```

How to fetch only Public or Private IP?

Thanks in Advance !

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 15, 2020, 9:02pm UTC](https://discuss.elastic.co/t/how-to-fetch-only-public-or-private-ip-in-es/248717/2 "2020-09-15T21:02:58Z")

</div>

[Queries on "ip\_range" type (missing documentation)](https://discuss.elastic.co/t/queries-on-ip-range-type-missing-documentation/246445/3) has some good pointers on that.

---

<div class="post-metadata">

**Author:** ![Ramesh\_balasubramani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramesh_balasubramani/32/53173_2.png) [@Ramesh\_balasubramani](https://discuss.elastic.co/u/Ramesh_balasubramani)\
**Post date:** [September 16, 2020, 5:26am UTC](https://discuss.elastic.co/t/how-to-fetch-only-public-or-private-ip-in-es/248717/3 "2020-09-16T05:26:09Z")

</div>

Thanks for your quick response.

But I need to filter only public IP  
eg.,

```
GET logstash-ramesh-2020.09.16/_search
{
   "query": {
      "bool": {
          "must_not": [
             {
                 "regexp": {
                    "src_ip.raw": {
                       "value": "^(?:10|127|172\\.(?:1[6-9]|2[0-9]|3[01])|192\\.168)\\..*"
                    }
                 }
             }
          ]
      }
   },
   "_source": [
      "src_ip"
   ]
}
```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 16, 2020, 9:53am UTC](https://discuss.elastic.co/t/how-to-fetch-only-public-or-private-ip-in-es/248717/4 "2020-09-16T09:53:15Z")

</div>

You can also try to use the `ip` data type, if your queries can be expressed using CIDR

```auto
DELETE my-index

PUT my-index
{
  "mappings": {
    "properties": {
      "ip_addr": {
        "type": "ip"
      }
    }
  }
}

PUT my-index/_bulk?refresh
{"index":{}}
{"ip_addr":"192.168.1.1"}
{"index":{}}
{"ip_addr":"1.1.1.1"}
{"index":{}}
{"ip_addr":"10.5.6.7"}

GET my-index/_search
{
  "query": {
    "terms": {
      "ip_addr": [
        "192.168.0.0/16",
        "127.16.0.0/16",
        "10.0.0.0/8"
      ]
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 14, 2020, 10:28am UTC](https://discuss.elastic.co/t/how-to-fetch-only-public-or-private-ip-in-es/248717/6 "2020-10-14T10:28:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
