# Indexing CIDR block e.g.: 192.168.1.0/24

**URL:** https://discuss.elastic.co/t/indexing-cidr-block-e-g-192-168-1-0-24/128036
**Category:** Elasticsearch
**Created:** [April 14, 2018, 4:20am UTC](https://discuss.elastic.co/t/indexing-cidr-block-e-g-192-168-1-0-24/128036 "2018-04-14T04:20:54Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![vramakrishnan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vramakrishnan/32/31750_2.png) [@vramakrishnan](https://discuss.elastic.co/u/vramakrishnan)
#### Post date: [April 14, 2018, 4:20am UTC](https://discuss.elastic.co/t/indexing-cidr-block-e-g-192-168-1-0-24/128036/1 "2018-04-14T04:20:54Z")

</div>

Is there a solution to index fields in CIDR block format and have the same "ip" datatype like functionality with CIDR query. ?

Using ip-type mapping, I got this error.

```
"error": {
    "root_cause": [
        {
            "type": "mapper_parsing_exception",
            "reason": "failed to parse [ip_addr]"
        }
    ],
    "type": "mapper_parsing_exception",
    "reason": "failed to parse [ip_addr]",
    "caused_by": {
        "type": "illegal_argument_exception",
        "reason": "'192.168.1.0/24' is not an IP string literal."
    }
```

---

<div class="post-metadata">

### Author: ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)
#### Post date: [April 14, 2018, 6:37am UTC](https://discuss.elastic.co/t/indexing-cidr-block-e-g-192-168-1-0-24/128036/2 "2018-04-14T06:37:29Z")

</div>

Can you show your mapping and the query you're sending?

---

<div class="post-metadata">

### Author: ![vramakrishnan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vramakrishnan/32/31750_2.png) [@vramakrishnan](https://discuss.elastic.co/u/vramakrishnan)
#### Post date: [April 14, 2018, 4:25pm UTC](https://discuss.elastic.co/t/indexing-cidr-block-e-g-192-168-1-0-24/128036/3 "2018-04-14T16:25:38Z")

</div>

Hi

Here is the mapping :

```auto
PUT http://192.168.128.32:7013/testindex

{
  "mappings": {
    "_doc": {
      "properties": {
        "ip_addr": {
          "type": "ip"
        }
      }
    }
  }
}

```

Here is the index PUT request:

```auto
PUT http://192.168.128.32:7013/testindex/_doc/2
{
  "ip_addr": "192.168.1.0/24"
}

And the request fails with ...

"error": {
    "root_cause": [
        {
            "type": "mapper_parsing_exception",
            "reason": "failed to parse [ip_addr]"
        }
    ],
    "type": "mapper_parsing_exception",
    "reason": "failed to parse [ip_addr]",
    "caused_by": {
        "type": "illegal_argument_exception",
        "reason": "'192.168.1.0/24' is not an IP string literal."
    }
}

```

---

<div class="post-metadata">

### Author: ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)
#### Post date: [April 14, 2018, 4:52pm UTC](https://discuss.elastic.co/t/indexing-cidr-block-e-g-192-168-1-0-24/128036/4 "2018-04-14T16:52:17Z")

</div>

If I'm not mistaken you can only search CIDR blocks but not index them

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [April 14, 2018, 4:55pm UTC](https://discuss.elastic.co/t/indexing-cidr-block-e-g-192-168-1-0-24/128036/5 "2018-04-14T16:55:42Z")

</div>

You can index it as a range with [https://www.elastic.co/guide/en/elasticsearch/reference/6.2/range.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/range.html)

---

<div class="post-metadata">

### Author: ![vramakrishnan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vramakrishnan/32/31750_2.png) [@vramakrishnan](https://discuss.elastic.co/u/vramakrishnan)
#### Post date: [April 14, 2018, 9:24pm UTC](https://discuss.elastic.co/t/indexing-cidr-block-e-g-192-168-1-0-24/128036/6 "2018-04-14T21:24:29Z")

</div>

ip\_range works great, thanks for the suggestion. Term query on this works well.

Is full text search possible on ip\_range fields ?

I have this mapping and text search failed on this ip-range. Wondering if there is solution to achieve this.

```auto
curl localhost:10201/ipindex/_mapping?pretty
{
  "ipindex" : {
    "mappings" : {
      "_doc" : {
        "properties" : {
          "dst_ip" : {
            "type" : "ip_range"
          },
          "src_ip" : {
            "type" : "ip_range"
          }
        }
      }
    }
  }
}

$ curl localhost:10201/ipindex/_search
{"took":2,"timed_out":false,"_shards":{"total":5,"successful":5,"skipped":0,"failed":0},"hits":{"total":1,"max_score":1.0,"hits":[{"_index":"ipindex","_type":"_doc","_id":"1","_score":1.0,"_source":{
  "src_ip": "10.2.0.0/16",
  "dst_ip": "10.3.0.128/29"
}
}]}}

$ curl localhost:10201/ipindex/_search?q=10.2.0.0
{"took":4,"timed_out":false,"_shards":{"total":5,"successful":5,"skipped":0,"failed":0},**"hits":{"total":0,"max_score":null,"hits":[]**}}

$ curl localhost:10201/ipindex/_search?q=src_ip:10.2.1.254
{"took":3,"timed_out":false,"_shards":{"total":5,"successful":5,"skipped":0,"failed":0},"hits":{"total":1,"max_score":1.0,"hits":[{"_index":"ipindex","_type":"_doc","_id":"1","_score":1.0,"_source":{
  "src_ip": "10.2.0.0/16",
  "dst_ip": "10.3.0.128/29"
}
}]}}

```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 12, 2018, 9:24pm UTC](https://discuss.elastic.co/t/indexing-cidr-block-e-g-192-168-1-0-24/128036/7 "2018-05-12T21:24:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
