# Logstash filter if internal networks

**URL:** <https://discuss.elastic.co/t/logstash-filter-if-internal-networks/309238>\
**Category:** Logstash\
**Created:** [July 9, 2022, 12:27am UTC](https://discuss.elastic.co/t/logstash-filter-if-internal-networks/309238 "2022-07-09T00:27:11Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![VamPikmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vampikmin/32/22367_2.png) [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Post date:** [July 9, 2022, 12:27am UTC](https://discuss.elastic.co/t/logstash-filter-if-internal-networks/309238/1 "2022-07-09T00:27:11Z")

</div>

This is a continuation of my previous thread which Badger kindly solved.

I have sflow data coming in with the src\_ip and dst\_ip fields

My internal networks are in this range and I'd like them not to be scanned for geoip:

```auto
filter {
      cidr {
        add_tag => ["Internal1"]
        address => ["%{src_ip}", "%{dst_ip}"]
        network => ["192.168.0.0/17"]
      }
    }

filter {
      cidr {
        add_tag => ["Internal2"]
        address => ["%{src_ip}", "%{dst_ip}"]
        network => ["192.168.128.0/17"]
      }
    }

```

I've tried this and it's not working, it tags external ip addresses as local and doesn't check for geoip

```auto
filter{
 if "Internal1" in [tags] or "Internal2" in [tags] {
        mutate {
                add_tag => "Local"}
        }

  else {
  geoip {
     default_database_type => "ASN"
     add_tag => ["GeoIP-DST"]
     source => "dst_ip"
     target => "destination"
     }

     geoip {
     default_database_type => "ASN"
     add_tag => ["GeoIP-SRC"]
     source => "src_ip"
     target => "source"
     }
}
}

```

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 9, 2022, 1:24am UTC](https://discuss.elastic.co/t/logstash-filter-if-internal-networks/309238/2 "2022-07-09T01:24:19Z")

</div>

If either the [src\_ip] or [dst\_ip] fields match either local network, you do not do the geoip lookup. I would do this

```
  cidr {
    add_tag => ["LocalSrc"]
    address => ["%{src_ip}"]
    network => ["192.168.0.0/17", "192.168.128.0/17"]
  }
  cidr {
    add_tag => ["LocalDst"]
    address => ["%{dst_ip}"]
    network => ["192.168.0.0/17", "192.168.128.0/17"]
  }
if "LocalDst" not in [tags] {
    geoip {
        default_database_type => "ASN"
        add_tag => ["GeoIP-DST"]
        source => "dst_ip"
        target => "destination"
    }
}
if "LocalSrc" not in [tags] {
     geoip {
         default_database_type => "ASN"
         add_tag => ["GeoIP-SRC"]
         source => "src_ip"
         target => "source"
     }
}

```

This will create event with tags like

```
       "tags" => [
    [0] "LocalSrc",
    [1] "GeoIP-DST"
],

      "tags" => [
    [0] "LocalDst",
    [1] "GeoIP-SRC"
],
       "tags" => [
    [0] "GeoIP-DST",
    [1] "GeoIP-SRC"
],

```

---

<div class="post-metadata">

**Author:** ![VamPikmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vampikmin/32/22367_2.png) [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Post date:** [July 9, 2022, 5:07am UTC](https://discuss.elastic.co/t/logstash-filter-if-internal-networks/309238/3 "2022-07-09T05:07:01Z")

</div>

Once again that worked like a charm. Thank you very much

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 6, 2022, 5:07am UTC](https://discuss.elastic.co/t/logstash-filter-if-internal-networks/309238/4 "2022-08-06T05:07:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
