# Mark IP Value with an external list

**URL:** <https://discuss.elastic.co/t/mark-ip-value-with-an-external-list/69055>\
**Category:** Logstash\
**Created:** [December 14, 2016, 4:50pm UTC](https://discuss.elastic.co/t/mark-ip-value-with-an-external-list/69055 "2016-12-14T16:50:33Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vomitar](https://avatars.discourse-cdn.com/v4/letter/v/f07891/32.png) [@Vomitar](https://discuss.elastic.co/u/Vomitar)\
**Post date:** [December 14, 2016, 4:50pm UTC](https://discuss.elastic.co/t/mark-ip-value-with-an-external-list/69055/1 "2016-12-14T16:50:33Z")

</div>

Hallo to everyone, it's my first topic here.  
scenario  
I have to check if some IP are SECURE and i do it checking the value (send me by apache logs) by an external list and so i have to mark or add a field .

Here an example with a static variable

if [clientip] == "192.168.0.1" {  
mutate { add\_field =\> ["ORIGIN", "SAFE"] }  
} else {  
mutate { add\_field =\> ["ORIGIN", "MALICIOUS"]}  
}

now I have to do the same but i must check the IP with a list (txt,csv etc) external.  
I have tried to do with ruby :

if [clientip] != '' {  
ruby {  
code =\>"  
f = File.new("list.ip")  
text = f.read  
if text =~ event['clientip'] then  
event[ORIGIN] = 'MALICIOUS'  
end  
"  
}  
}

Can You help me ? Thank you

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 14, 2016, 4:53pm UTC](https://discuss.elastic.co/t/mark-ip-value-with-an-external-list/69055/2 "2016-12-14T16:53:27Z")

</div>

Have you looked at the [translate plugin](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html)?

---

<div class="post-metadata">

**Author:** ![Vomitar](https://avatars.discourse-cdn.com/v4/letter/v/f07891/32.png) [@Vomitar](https://discuss.elastic.co/u/Vomitar)\
**Post date:** [December 14, 2016, 4:55pm UTC](https://discuss.elastic.co/t/mark-ip-value-with-an-external-list/69055/3 "2016-12-14T16:55:51Z")

</div>

thank you for the answer, yes i have looked but i don't know if is the better way ...

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 14, 2016, 4:57pm UTC](https://discuss.elastic.co/t/mark-ip-value-with-an-external-list/69055/4 "2016-12-14T16:57:12Z")

</div>

It does cache the dictionary, so I would expect it to be considerably more efficient than a Ruby filter.

---

<div class="post-metadata">

**Author:** ![Vomitar](https://avatars.discourse-cdn.com/v4/letter/v/f07891/32.png) [@Vomitar](https://discuss.elastic.co/u/Vomitar)\
**Post date:** [December 14, 2016, 5:00pm UTC](https://discuss.elastic.co/t/mark-ip-value-with-an-external-list/69055/5 "2016-12-14T17:00:59Z")

</div>

Yes , load the list in RAM is more efficent but i don't know how to use the plugin for my needs

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 15, 2016, 9:52am UTC](https://discuss.elastic.co/t/mark-ip-value-with-an-external-list/69055/6 "2016-12-15T09:52:49Z")

</div>

Create a dictionary with all SECURE IPs mapped to e.g. the string 'SECURE'. The create a lookup and populate a field with this. If the field then is not set you can assume it is not secure and label it MALICIOUS. Would that work?

---

<div class="post-metadata">

**Author:** ![Vomitar](https://avatars.discourse-cdn.com/v4/letter/v/f07891/32.png) [@Vomitar](https://discuss.elastic.co/u/Vomitar)\
**Post date:** [December 15, 2016, 11:41am UTC](https://discuss.elastic.co/t/mark-ip-value-with-an-external-list/69055/7 "2016-12-15T11:41:56Z")

</div>

If i undestood translate , transform a variable in other ... ad ex , IP convert in SECURE (or not SECURE) , i need match the variable with a list for mark an additional FLAG with the keyword.  
My solutions :

```
   ruby { code => "
    f = File.open('/tmp/IP.lst','r')
    ip = event['clientip']
    text = f.read()
    if text =~ /#{ip}/
      event['ORIGIN'] = 'SECURE'
    else
      event['ORIGIN'] = 'MALICIOUS'
    end
      f.close()
    puts event['ORIGIN']
  "}
```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 15, 2016, 12:02pm UTC](https://discuss.elastic.co/t/mark-ip-value-with-an-external-list/69055/8 "2016-12-15T12:02:52Z")

</div>

Translate allows you to perform a lookup against a dictionary based on the contents of a field, e.g. `clientip`, and populate a different field with the result, which could be `SECURE` or `MALICIOUS` as in your example. You could combine this with a conditional (the field containing the result of the lookup is not set) and use a mutate filter to then set it to `MALICIOUS`, which would be the default value. This should do what your Ruby filter does but avoid loading the file once for every event.

---

<div class="post-metadata">

**Author:** ![Vomitar](https://avatars.discourse-cdn.com/v4/letter/v/f07891/32.png) [@Vomitar](https://discuss.elastic.co/u/Vomitar)\
**Post date:** [December 15, 2016, 12:04pm UTC](https://discuss.elastic.co/t/mark-ip-value-with-an-external-list/69055/9 "2016-12-15T12:04:45Z")

</div>

Can you help me please ? I'd like use translate but don't know how to use it combinated with a conditional

thank you very much

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 15, 2016, 1:49pm UTC](https://discuss.elastic.co/t/mark-ip-value-with-an-external-list/69055/10 "2016-12-15T13:49:59Z")

</div>

Have you had a look at the documentation? What have you tried so far?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 12, 2017, 1:50pm UTC](https://discuss.elastic.co/t/mark-ip-value-with-an-external-list/69055/11 "2017-01-12T13:50:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
