# How to store array of IP?

**URL:** <https://discuss.elastic.co/t/how-to-store-array-of-ip/51461>\
**Category:** Elasticsearch\
**Created:** [May 31, 2016, 4:57pm UTC](https://discuss.elastic.co/t/how-to-store-array-of-ip/51461 "2016-05-31T16:57:02Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![esamudio](https://avatars.discourse-cdn.com/v4/letter/e/df788c/32.png) [@esamudio](https://discuss.elastic.co/u/esamudio)\
**Post date:** [May 31, 2016, 4:57pm UTC](https://discuss.elastic.co/t/how-to-store-array-of-ip/51461/1 "2016-05-31T16:57:02Z")

</div>

I have noticed that I'm unable to create an array of IP the same way I can create an array of either integers or strings as it doesn't seem to be recognized by default. Is there a way for me to create an array of IP?

If it helps, if someone knows how ES interprets an IP (as documentation says its stored as a long), I'm also open to suggestions as I can write up code to parse the IPs into whatever format ES converts it to so I can possibly create an array of longs and store them as IP?

Thanks for the help!

---

<div class="post-metadata">

**Author:** ![msimos](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@msimos](https://discuss.elastic.co/u/msimos)\
**Post date:** [May 31, 2016, 6:59pm UTC](https://discuss.elastic.co/t/how-to-store-array-of-ip/51461/2 "2016-05-31T18:59:29Z")

</div>

Hi,

You should be able to use a mapping like:

```auto
PUT ips
{
  "mappings": {
    "type": {
      "properties": {
        "ips" : {
          "type": "ip"
        }
      }
    }
  }
}

```

Index a document like this:

```auto
POST ips/type
{
  "ips": ["123.123.123.123","10.0.0.1"]
}

```

Then you can search using something like this:

```auto
GET /ips/_search
{
  "query": {
    "term": {
      "ips": {
        "value": "10.0.0.1"
      }
    }
  }
}

```

Which results in a match of the following document:

```auto
 "hits": {
    "total": 1,
    "max_score": 0.30685282,
    "hits": [
      {
        "_index": "ips",
        "_type": "type",
        "_id": "AVUILG5rcBlij3ua9lEz",
        "_score": 0.30685282,
        "_source": {
          "ips": [
            "123.123.123.123",
            "10.0.0.1"
          ]
        }
      }
    ]
  }

```

---

<div class="post-metadata">

**Author:** ![esamudio](https://avatars.discourse-cdn.com/v4/letter/e/df788c/32.png) [@esamudio](https://discuss.elastic.co/u/esamudio)\
**Post date:** [June 1, 2016, 1:05am UTC](https://discuss.elastic.co/t/how-to-store-array-of-ip/51461/3 "2016-06-01T01:05:25Z")

</div>

Thanks for the answer!

I tried doing that as the documentation says that any field can be an array by just appending elements. The problem that occurred is that ES would give an error saying there was a mismatch in between arrays of type long vs type IP (expected by mapping). Would you know if there's a way around this?

---

<div class="post-metadata">

**Author:** ![msimos](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@msimos](https://discuss.elastic.co/u/msimos)\
**Post date:** [June 1, 2016, 1:51am UTC](https://discuss.elastic.co/t/how-to-store-array-of-ip/51461/4 "2016-06-01T01:51:43Z")

</div>

Hi,

Sorry I don't understand the question. I provided you an example of how you would create an array of type ip. Is there something as to what I demonstrated that doesn't meet your needs? You just need to use square brackets to specify an array in your document as I demonstrated above.

---

<div class="post-metadata">

**Author:** ![esamudio](https://avatars.discourse-cdn.com/v4/letter/e/df788c/32.png) [@esamudio](https://discuss.elastic.co/u/esamudio)\
**Post date:** [June 1, 2016, 10:28am UTC](https://discuss.elastic.co/t/how-to-store-array-of-ip/51461/5 "2016-06-01T10:28:29Z")

</div>

It's my fault for not providing enough information/being clear enough. I followed your instructions as listed and I'm not sure if I'm doing something wrong because I get the following exception:

> {"error":{"root\_cause":[{"type":"mapper\_parsing\_exception","reason":"failed to parse"}],"type":"mapper\_parsing\_exception","reason":"failed to parse","caused\_by":{"type":"illegal\_state\_exception","reason":"Mixing up field types: class org.elasticsearch.index.mapper.core.LongFieldMapper$LongFieldType != class org.elasticsearch.index.mapper.ip.IpFieldMapper$IpFieldType on field ips"}},"status":400}

That's what happened when I first tried to make an array of IPs and I'm not sure how to circumvent that.

---

<div class="post-metadata">

**Author:** ![msimos](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@msimos](https://discuss.elastic.co/u/msimos)\
**Post date:** [June 2, 2016, 2:28am UTC](https://discuss.elastic.co/t/how-to-store-array-of-ip/51461/6 "2016-06-02T02:28:44Z")

</div>

Can you provide the mapping and a sample document you're trying to index?

---

<div class="post-metadata">

**Author:** ![esamudio](https://avatars.discourse-cdn.com/v4/letter/e/df788c/32.png) [@esamudio](https://discuss.elastic.co/u/esamudio)\
**Post date:** [June 2, 2016, 4:44pm UTC](https://discuss.elastic.co/t/how-to-store-array-of-ip/51461/7 "2016-06-02T16:44:20Z")

</div>

I created a dummy index following the steps above. My dummy index is called "com".

```
curl -XPUT 'http://localhost:9200/com' -d '{
	"mappings": {
		"type": {
			"properties": {
				"ips": {
					"type": "ip"
				}
			}
		}
	}
}'

```

I then indexed the sample ip array into the "com" index in the "anytype" type with id "1".

```
curl -XPOST 'http://localhost:9200/com/anytype/1' -d '{
	"ips": ["123.123.123.123", "10.0.0.1"]
}'

```

This gave me the error:

```
{
	"error": {
		"root_cause": [{
			"type": "mapper_parsing_exception",
			"reason": "failed to parse"
		}],
		"type": "mapper_parsing_exception",
		"reason": "failed to parse",
		"caused_by": {
			"type": "illegal_state_exception",
			"reason": "Mixing up field types: class org.elasticsearch.index.mapper.core.LongFieldMapper$LongFieldType != class org.elasticsearch.index.mapper.ip.IpFieldMapper$IpFieldType on field ips"
		}
	},
	"status": 400
}

```

I appreciate you taking the time to help me debug this 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:46pm UTC](https://discuss.elastic.co/t/how-to-store-array-of-ip/51461/8 "2017-07-05T22:46:48Z")

</div>


