# Regex express to eliminate private address space from geoip

**URL:** <https://discuss.elastic.co/t/regex-express-to-eliminate-private-address-space-from-geoip/217677>\
**Category:** Logstash\
**Created:** [February 3, 2020, 6:57pm UTC](https://discuss.elastic.co/t/regex-express-to-eliminate-private-address-space-from-geoip/217677 "2020-02-03T18:57:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![DWbank](https://avatars.discourse-cdn.com/v4/letter/d/d6d6ee/32.png) [@DWbank](https://discuss.elastic.co/u/DWbank)\
**Post date:** [February 3, 2020, 6:57pm UTC](https://discuss.elastic.co/t/regex-express-to-eliminate-private-address-space-from-geoip/217677/1 "2020-02-03T18:57:41Z")

</div>

I am trying to eliminate private address spacing going through geoip. I am guessing my regexp is not quite right, seems to still match everything.

```
################### This checks to see that address is not internal for geoip

if [src_ip] !~ /^127\./ or [src_ip] !~ /^10\./ or [src_ip] !~ /^172\.1[6-9]\./ or [src_ip] !~ /^172\.2[0-9]\./ or [src_ip] !~ /^172\.3[0-1]\./ or [src_ip] !~ /^192\.168\./
{
        geoip {
                source => "src_ip"
                target => "geoip"
                add_field => ["[geoip][coordinates]", "%{[geoip][longitude]}" ]
                add_field => ["[geoip][coordinates]", "%{[geoip][latitude]}" ]
        }

mutate {
        convert => ["[geoip][coordinates]", "float"]
        }
}

```

Maybe there is a easier way to write that too.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 3, 2020, 7:39pm UTC](https://discuss.elastic.co/t/regex-express-to-eliminate-private-address-space-from-geoip/217677/2 "2020-02-03T19:39:24Z")

</div>

Use a cidr filter. [This](https://discuss.elastic.co/t/tagging-for-public-ip-address/183433/8) post has an example tagging those networks.

---

<div class="post-metadata">

**Author:** ![DWbank](https://avatars.discourse-cdn.com/v4/letter/d/d6d6ee/32.png) [@DWbank](https://discuss.elastic.co/u/DWbank)\
**Post date:** [February 3, 2020, 8:49pm UTC](https://discuss.elastic.co/t/regex-express-to-eliminate-private-address-space-from-geoip/217677/3 "2020-02-03T20:49:10Z")

</div>

@Badger,

That worked Thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 2, 2020, 8:49pm UTC](https://discuss.elastic.co/t/regex-express-to-eliminate-private-address-space-from-geoip/217677/4 "2020-03-02T20:49:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
