# Logstash CIDR Filter : create new field with matched network

**URL:** <https://discuss.elastic.co/t/logstash-cidr-filter-create-new-field-with-matched-network/266282>\
**Category:** Logstash\
**Created:** [March 4, 2021, 7:54pm UTC](https://discuss.elastic.co/t/logstash-cidr-filter-create-new-field-with-matched-network/266282 "2021-03-04T19:54:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nybble](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nybble/32/49569_2.png) [@Nybble](https://discuss.elastic.co/u/Nybble)\
**Post date:** [March 4, 2021, 7:54pm UTC](https://discuss.elastic.co/t/logstash-cidr-filter-create-new-field-with-matched-network/266282/1 "2021-03-04T19:54:33Z")

</div>

Hello,

I'm currently using the Logstash CIDR filter to tag private and public IP.

Now, I want to use this plugin with a list of all the networks used within my company and add a field or a tag with network information when there is a match.

Example :

logstash-cidr.conf

```auto
filter {
      cidr {
          add_tag => ["%{matched_network}"]
          address => ["%{[source][ip]}" ]
          network_path => "/my/network/path/cmdb.csv"
      }
} 

```

cmdb.csv

```auto
10.1.1.0/24
10.2.0.0/20

```

In case 'source.ip': '10.1.1.10', tag is ["10.1.1.0/24"].

Do anyone know how to retrieve the matched network range directly ?

The final goal is to use an Ingest Pipepline to then enrich events with network range information.

Thanks !  
Sébastien.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 4, 2021, 9:45pm UTC](https://discuss.elastic.co/t/logstash-cidr-filter-create-new-field-with-matched-network/266282/2 "2021-03-04T21:45:42Z")

</div>

> [@Nybble](#):
>
> Do anyone know how to retrieve the matched network range directly ?

You cannot do that. If you look at the code, you will see that if it finds a match all it does it decorate the event (i.e. process the add\_tag, remove\_tag, add\_field, and remove\_field options).

There is an open issue requesting this [here](https://github.com/logstash-plugins/logstash-filter-cidr/issues/16). That suggests a PR was submitted recently (which is [here](https://github.com/logstash-plugins/logstash-filter-cidr/pull/25), but it contains several other changes). There is also [this PR](https://github.com/logstash-plugins/logstash-filter-cidr/issues/24) that was submitted last year. As you can see it is a minor change. Unfortunately it is just a comment that contains the required code changes, it is not packaged as a PR. If someone repackaged it then it is at least possible that it would get merged.

As far as I know the state of the art in workarounds is to use an external program that maps every range to a list of addresses and range like this:

```
192.168.3.4,192.168.3.4/31
192.168.3.5,192.168.3.4/31
192.168.3.6,192.168.3.6/30
192.168.3.7,192.168.3.6/30
192.168.3.8,192.168.3.6/30
192.168.3.9,192.168.3.6/30
192.168.3.10,192.168.3.10/31
192.168.3.11,192.168.3.10/31

```

Then pass that to a translate filter (at which point you do not need a cidr filter).  
And yes, I am aware that for a large corporation that file could contain over a million lines. That will not bother a translate filter.

---

<div class="post-metadata">

**Author:** ![Nybble](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nybble/32/49569_2.png) [@Nybble](https://discuss.elastic.co/u/Nybble)\
**Post date:** [March 5, 2021, 6:22am UTC](https://discuss.elastic.co/t/logstash-cidr-filter-create-new-field-with-matched-network/266282/3 "2021-03-05T06:22:03Z")

</div>

Many thanks for the answer !

Nice for the PR, it will be a usefull feature 🙂

But if the translate filter can support a million of lines, it should be totally fine for my use case too 🙂

Sébastien.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 2, 2021, 6:22am UTC](https://discuss.elastic.co/t/logstash-cidr-filter-create-new-field-with-matched-network/266282/4 "2021-04-02T06:22:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
