# Search thru an IP blocklist

**URL:** <https://discuss.elastic.co/t/search-thru-an-ip-blocklist/58560>\
**Category:** Kibana\
**Created:** [August 22, 2016, 9:09am UTC](https://discuss.elastic.co/t/search-thru-an-ip-blocklist/58560 "2016-08-22T09:09:48Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Laverio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/laverio/32/135588_2.png) [@Laverio](https://discuss.elastic.co/u/Laverio)\
**Post date:** [August 22, 2016, 9:09am UTC](https://discuss.elastic.co/t/search-thru-an-ip-blocklist/58560/1 "2016-08-22T09:09:48Z")

</div>

Hi, I'm new to the ELK stack and I'm looking for a way to filter my apache logs using an ip blocklist. There a way thru the Kibana GUI or I have to work directly on Logstash?

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [August 22, 2016, 10:41am UTC](https://discuss.elastic.co/t/search-thru-an-ip-blocklist/58560/2 "2016-08-22T10:41:47Z")

</div>

assuming your data was correctly indexed (clientip field from your apache logs should be of [IP type](https://www.elastic.co/guide/en/elasticsearch/reference/current/ip.html)) you then have two options:

1. in visualizations you can aggregate on ip range (so ips from one range go to one bucket, ips from some other ranges to other buckets). just go to visualize, choose your visualization (lets say pie), click on split slices and then select IPv4 range as aggregation type

2. filter your existing visualizations on IP ranges:  
in the searchbox (where you have \* at the moment to select all records) put a range filter on clientip field:  
`clientip:[1.168.1.100 TO 120.168.1.102]`

---

<div class="post-metadata">

**Author:** ![Laverio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/laverio/32/135588_2.png) [@Laverio](https://discuss.elastic.co/u/Laverio)\
**Post date:** [August 22, 2016, 11:13am UTC](https://discuss.elastic.co/t/search-thru-an-ip-blocklist/58560/3 "2016-08-22T11:13:48Z")

</div>

So, I've to list all the IPs manually, is it not possible to use another index or a text file?

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [August 22, 2016, 11:34am UTC](https://discuss.elastic.co/t/search-thru-an-ip-blocklist/58560/4 "2016-08-22T11:34:52Z")

</div>

i guess you could use a text editor to properly format your blocks and then copy paste to kibana

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:40pm UTC](https://discuss.elastic.co/t/search-thru-an-ip-blocklist/58560/5 "2017-07-06T13:40:40Z")

</div>


