# Logstash filter cidr error

**URL:** <https://discuss.elastic.co/t/logstash-filter-cidr-error/73187>\
**Category:** Logstash\
**Created:** [January 30, 2017, 10:34am UTC](https://discuss.elastic.co/t/logstash-filter-cidr-error/73187 "2017-01-30T10:34:29Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![ANU\_SARA\_VARGHESE](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anu_sara_varghese/32/51487_2.png) [@ANU\_SARA\_VARGHESE](https://discuss.elastic.co/u/ANU_SARA_VARGHESE)\
**Post date:** [January 30, 2017, 10:34am UTC](https://discuss.elastic.co/t/logstash-filter-cidr-error/73187/1 "2017-01-30T10:34:29Z")

</div>

Hi,

I was trying CIDR filter of logstash.

cidr {  
add\_tag =\> ["matched"]  
address =\> ["%{clientip}"]  
network =\> ["10.123.123.0/24", "10.xxx.xxx.0/24", "10.xxx.xxx.0/24", "10.xxx.xxx.0/24"]  
}

This is giving an error when there is any other IP, other than, the 10 series i.e. external public IPs.

The error is

Invalid IP address, skipping {:address=\>"%{clientip}", :event=\>#\<LogStash::Event:0x3ff5aaeb @metadata\_accessors=#\<LogStash::Util::Accessors:0x6bbb121a @store={}, @lut={}\>, @cancelled=false, @data={...... ......:level=\>:warn}

How to remove this error?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 30, 2017, 11:04am UTC](https://discuss.elastic.co/t/logstash-filter-cidr-error/73187/2 "2017-01-30T11:04:04Z")

</div>

This is because the event didn't have a `clientip` field.

---

<div class="post-metadata">

**Author:** ![ANU\_SARA\_VARGHESE](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anu_sara_varghese/32/51487_2.png) [@ANU\_SARA\_VARGHESE](https://discuss.elastic.co/u/ANU_SARA_VARGHESE)\
**Post date:** [January 30, 2017, 1:12pm UTC](https://discuss.elastic.co/t/logstash-filter-cidr-error/73187/3 "2017-01-30T13:12:55Z")

</div>

Thanks Magnus for reply.

There are clientip field simuntaneously with the geoip.ip field in the same event. Such events are throwing error.  
How can I bypass such events ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 30, 2017, 1:35pm UTC](https://discuss.elastic.co/t/logstash-filter-cidr-error/73187/4 "2017-01-30T13:35:27Z")

</div>

To only run the cidr filter if there's a `clientip` field:

```nohighlight
if [clientip] {
  cidr {
    ...
  }
}

```

---

<div class="post-metadata">

**Author:** ![ANU\_SARA\_VARGHESE](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anu_sara_varghese/32/51487_2.png) [@ANU\_SARA\_VARGHESE](https://discuss.elastic.co/u/ANU_SARA_VARGHESE)\
**Post date:** [January 31, 2017, 8:41am UTC](https://discuss.elastic.co/t/logstash-filter-cidr-error/73187/5 "2017-01-31T08:41:29Z")

</div>

Hi Magnus,

I tried this. But it is not working. Both clientip and geoip.ip fileds exist together in same event.

So same error has occurred.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 31, 2017, 8:48am UTC](https://discuss.elastic.co/t/logstash-filter-cidr-error/73187/6 "2017-01-31T08:48:31Z")

</div>

Sorry, I don't understand. What does the `[geoip][ip]` field have to do with this? What does a failing event look like? Use a `stdout { codec => rubydebug }` output.

---

<div class="post-metadata">

**Author:** ![ANU\_SARA\_VARGHESE](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anu_sara_varghese/32/51487_2.png) [@ANU\_SARA\_VARGHESE](https://discuss.elastic.co/u/ANU_SARA_VARGHESE)\
**Post date:** [January 31, 2017, 9:40am UTC](https://discuss.elastic.co/t/logstash-filter-cidr-error/73187/7 "2017-01-31T09:40:44Z")

</div>

Hi Magnus,

The event is:  
\<157\>Nov 30 20:21:43 hostname process: 10.xx.x.x 47.xxx.xx.x ip3.host.domain [30/Nov/2016:20:21:43 +0530] - "POST /url/xxx/url/xx HTTP/1.1" 200 29 "-" "Apache-HttpClient/UNAVAILABLE (java 1.4)" 0.008 0.008 .

This has 3 clientip., with 1 extrenal ip (which then is the geoip)

This is the stdout for the event:

Invalid IP address, skipping {:address=\>"%{clientip}", :event=\>#\<LogStash::Event:0x14422092 @metadata\_accessors=#\<LogStash::Util::Accessors:0x12d16236 @store={}, @lut={}\>, @cancelled=false, @data={"message"=\>"\<157\>Nov 30 20:21:43 hostname process: 10.x.x.x 47.x.x.x ip3.host.domain [30/Nov/2016:20:21:43 +0530] - "POST url/x/url/x HTTP/1.1" 200 29 "-" "Apache-HttpClient/UNAVAILABLE (java 1.4)" 0.008 0.008 .", "@version"=\>"1", "@timestamp"=\>"2017-01-31T09:21:05.662Z", "host"=\>"anu", "tags"=\>["\_grokparsefailure", "weblogs\_3ips"], "timestamp"=\>"Nov 30 20:21:43", "logsource"=\>"hostname", "program"=\>"process", "clientip"=\>["10.x.x.x", "47.x.x.x", "ip3.host.domain"], "t"=\>"30/Nov/2016:20:21:43 +0530", "verb"=\>"POST", "request"=\>"/apis/jionetwork/v1/checklist\_v1.3/", "httpversion"=\>"1.1", "response"=\>"200", "bytes"=\>"29", "ref"=\>"-"}, @metadata={}, @accessors=#\<LogStash::Util::Accessors:0x169f9c46 @store={"message"=\>"\<157\>Nov 30 20:21:43 SMUMAPI002 nginx: 10.x.x.x 47.x.x.x ip3.host.domain [30/Nov/2016:20:21:43 +0530] - "POST /url/x/url/x HTTP/1.1" 200 29 "-" "Apache-HttpClient/UNAVAILABLE (java 1.4)" 0.008 0.008 .", "@version"=\>"1", "@timestamp"=\>"2017-01-31T09:21:05.662Z", "host"=\>"anu", "tags"=\>["\_grokparsefailure", "weblogs\_3ips"], "timestamp"=\>"Nov 30 20:21:43", "logsource"=\>hostname", "program"=\>"process", "clientip"=\>["10.x.x.x", "47.x.x.x", "ip3.host.domain"], "t"=\>"30/Nov/2016:20:21:43 +0530", "verb"=\>"POST", "request"=\>"/apis/jionetwork/v1/checklist\_v1.3/", "httpversion"=\>"1.1", "response"=\>"200", "bytes"=\>"29", "ref"=\>"-"}, @lut={"host"=\>[{"message"=\>"\<157\>Nov 30 20:21:43 hostname process: 10.x.x.x 47.x.x.x ip3.host.domain [30/Nov/2016:20:21:43 +0530] - "POST /apis/jionetwork/v1/checklist\_v1.3/ HTTP/1.1" 200 29 "-" "Apache-HttpClient/UNAVAILABLE (java 1.4)" 0.008 0.008 .", "@version"=\>"1", "@timestamp"=\>"2017-01-31T09:21:05.662Z", "host"=\>"anu", "tags"=\>["\_grokparsefailure", "weblogs\_3ips"], "timestamp"=\>"Nov 30 20:21:43", "logsource"=\>"hostname", "program"=\>"process", "clientip"=\>["10.x.x.x", "47.x.x.x", "ip3.host.domain"], "t"=\>"30/Nov/2016:20:21:43 +0530", "verb"=\>"POST", "request"=r"/url/x/url/x", "httpversion"=\>"1.1", "response"=\>"200", "bytes"=\>"29", "ref"=\>"-"}, "host"], ...........................repeats many times............................\>\>, :level=\>:warn}  
{  
"message" =\> "\<157\>Nov 30 20:21:43 hostname process: 10.xx.x.xx 47.x.x.xx ip3.host.domain [30/Nov/2016:20:21:43 +0530] - "POST /url/x/x/url/ HTTP/1.1" 200 29 "-" "Apache-HttpClient/UNAVAILABLE (java 1.4)" 0.008 0.008 .",  
"@version" =\> "1",  
"@timestamp" =\> "2017-01-31T09:21:05.662Z",  
"host" =\> "anu",  
"tags" =\> [  
[0] "\_grokparsefailure",  
[1] "weblogs\_3ips"  
],  
"timestamp" =\> "Nov 30 20:21:43",  
"logsource" =\> "hostname",  
"program" =\> "process",  
"clientip" =\> [  
[0] "10.x.x.x",  
[1] "47.x.x.x",  
[2] "ip3.host.domain"  
],  
"t" =\> "30/Nov/2016:20:21:43 +0530",  
"verb" =\> "POST",  
"request" =\> "/url/x/url/x/",  
"httpversion" =\> "1.1",  
"response" =\> "200",  
"bytes" =\> "29",  
"ref" =\> "-"  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 1, 2017, 6:52am UTC](https://discuss.elastic.co/t/logstash-filter-cidr-error/73187/8 "2017-02-01T06:52:12Z")

</div>

Which IP address would you like to use with the cidr filter? Please show your full configuration.

---

<div class="post-metadata">

**Author:** ![ANU\_SARA\_VARGHESE](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anu_sara_varghese/32/51487_2.png) [@ANU\_SARA\_VARGHESE](https://discuss.elastic.co/u/ANU_SARA_VARGHESE)\
**Post date:** [February 7, 2017, 5:07am UTC](https://discuss.elastic.co/t/logstash-filter-cidr-error/73187/9 "2017-02-07T05:07:13Z")

</div>

Hi Magnus,

The full configuration is

input { stdin {} }

filter {  
grok {

```
   match => {"message" => "%{COMMONAPACHELOG}"}

  }

```

grok {  
match =\> { "message" =\> "%{SYSLOGBASE} %{NUMBER:response} [%{HTTPDATE}] %{NUMBER} %{NUMBER} %{NUMBER} "(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})" %{IPORHOST:clientip} "}

```
  }

```

cidr {  
add\_tag =\> ["matched"]  
address =\> ["%{clientip}"]  
network =\> ["10.123.123.0/24", "10.xxx.xxx.0/24", "10.xxx.xxx.0/24", "10.xxx.xxx.0/24"]  
}

geoip {  
source =\> "clientip"  
target =\> "geoip"  
database =\> "/etc/logstash/GeoLiteCity.dat"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
add\_tag =\> ["geo"]  
}

mutate {  
convert =\> ["[geoip][coordinates]", "float"]  
}  
}

output { stdout {codec =\> rubydebug } }

---

<div class="post-metadata">

**Author:** ![ANU\_SARA\_VARGHESE](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anu_sara_varghese/32/51487_2.png) [@ANU\_SARA\_VARGHESE](https://discuss.elastic.co/u/ANU_SARA_VARGHESE)\
**Post date:** [February 7, 2017, 7:10am UTC](https://discuss.elastic.co/t/logstash-filter-cidr-error/73187/10 "2017-02-07T07:10:34Z")

</div>

Hi magnus,

The above configuration works well. But when I add this filter (below):

grok {  
match =\> { "message" =\> "%{SYSLOGBASE} %{IPORHOST:clientip} %{IPORHOST:clientip} %{IPORHOST:clientip} [%{HTTPDATE:t}] %{USER} "(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})" %{NUMBER:response} %{NUMBER:bytes} "%{USER:ref}" "}

```
  }

```

This has 3 clientips, which creates the conflict.

How can I remove this?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 7, 2017, 8:32am UTC](https://discuss.elastic.co/t/logstash-filter-cidr-error/73187/11 "2017-02-07T08:32:16Z")

</div>

If you don't want three IP addresses in the `clientip` field, don't list `%{IPORHOST:clientip}` three times. Capture the IP addresses to different fields.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 7, 2017, 8:32am UTC](https://discuss.elastic.co/t/logstash-filter-cidr-error/73187/12 "2017-03-07T08:32:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
