# Luceny query: 10.\* gives incorrect results such as 100.xxx

**URL:** <https://discuss.elastic.co/t/luceny-query-10-gives-incorrect-results-such-as-100-xxx/167059>\
**Category:** Kibana\
**Created:** [February 5, 2019, 5:37am UTC](https://discuss.elastic.co/t/luceny-query-10-gives-incorrect-results-such-as-100-xxx/167059 "2019-02-05T05:37:28Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sjaak01](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@Sjaak01](https://discuss.elastic.co/u/Sjaak01)\
**Post date:** [February 5, 2019, 5:37am UTC](https://discuss.elastic.co/t/luceny-query-10-gives-incorrect-results-such-as-100-xxx/167059/1 "2019-02-05T05:37:28Z")

</div>

Hi,

I'm trying to filter some IP's but for whatever reason something like source:10.\* will also show IP's in the 100.xxx etc. range while it should show only 10.xxx.

Using a similar query for 192.168.\* or 172.16.\* works without problems and returns only the correct ranges.

Why isn't this working for 10.\*?

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [February 5, 2019, 8:11pm UTC](https://discuss.elastic.co/t/luceny-query-10-gives-incorrect-results-such-as-100-xxx/167059/2 "2019-02-05T20:11:27Z")

</div>

What mapping are you using for the ip field? Is the field mapped as [IP type](https://www.elastic.co/guide/en/elasticsearch/reference/master/ip.html) or [keyword type](https://www.elastic.co/guide/en/elasticsearch/reference/master/keyword.html)?

When mapping as the `IP`, `*` did not return any matching results. When mapping as keywork, the query worked as expected

Below is a sample data set. Run the following scripts in Dev tools

```auto
PUT test
{}

PUT test/_mapping
{
  "properties": {
    "ip_addr": {
      "type": "keyword"
    }
  }
}

PUT test/_doc/1
{
  "ip_addr": "100.168.1.1"
}

PUT test/_doc/2
{
  "ip_addr": "10.168.1.1"
}

```

Then the query worked as expected

 ![22%20PM](https://us1.discourse-cdn.com/elastic/original/3X/1/2/12bbea664d9b9e1f9a424ce8a674aa92b7b4eca0.png)

---

<div class="post-metadata">

**Author:** ![Sjaak01](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@Sjaak01](https://discuss.elastic.co/u/Sjaak01)\
**Post date:** [February 5, 2019, 11:35pm UTC](https://discuss.elastic.co/t/luceny-query-10-gives-incorrect-results-such-as-100-xxx/167059/3 "2019-02-05T23:35:48Z")

</div>

Its mapped as a keyword. However the problem isn't that 10.\* doesn't return any results, the problem is that it returns too many results.

10.\* should only match 10.\* IP's, but instead it also matches IP's such as 100.\*.

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [February 5, 2019, 11:55pm UTC](https://discuss.elastic.co/t/luceny-query-10-gives-incorrect-results-such-as-100-xxx/167059/4 "2019-02-05T23:55:53Z")

</div>

I did not see that in the provided example. Can you show some of the matching results that you think should be shown? Do they have `10.` for any of the octets?

---

<div class="post-metadata">

**Author:** ![Sjaak01](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@Sjaak01](https://discuss.elastic.co/u/Sjaak01)\
**Post date:** [February 6, 2019, 8:07am UTC](https://discuss.elastic.co/t/luceny-query-10-gives-incorrect-results-such-as-100-xxx/167059/5 "2019-02-06T08:07:09Z")

</div>

Had to hide some of the data but there is no 10. anywhere in this example.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/b/7b58ab1496cfd6608558275020cf13faf229987c.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 6, 2019, 8:07am UTC](https://discuss.elastic.co/t/luceny-query-10-gives-incorrect-results-such-as-100-xxx/167059/6 "2019-03-06T08:07:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
