# Sorting for IP\[IPv4 & IPv6\]

**URL:** <https://discuss.elastic.co/t/sorting-for-ip-ipv4-ipv6/205361>\
**Category:** Elasticsearch\
**Created:** [October 26, 2019, 3:41pm UTC](https://discuss.elastic.co/t/sorting-for-ip-ipv4-ipv6/205361 "2019-10-26T15:41:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![singamsundeep](https://avatars.discourse-cdn.com/v4/letter/s/e36b37/32.png) [@singamsundeep](https://discuss.elastic.co/u/singamsundeep)\
**Post date:** [October 26, 2019, 3:41pm UTC](https://discuss.elastic.co/t/sorting-for-ip-ipv4-ipv6/205361/1 "2019-10-26T15:41:26Z")

</div>

Hi, Is that possible to do sorting for the Ip type? or should we convert to integer format and do sorting on the integer converted value.

---

<div class="post-metadata">

**Author:** ![singamsundeep](https://avatars.discourse-cdn.com/v4/letter/s/e36b37/32.png) [@singamsundeep](https://discuss.elastic.co/u/singamsundeep)\
**Post date:** [October 29, 2019, 3:55am UTC](https://discuss.elastic.co/t/sorting-for-ip-ipv4-ipv6/205361/2 "2019-10-29T03:55:43Z")

</div>

While doing sorting for IPv6 on ascending order seeing an issue in the sorted results?  
Is there any known issue in Elastic 6.2 version?

Seems like for IPv6 sorting based CIDR notation is not working.

{  
"size": 0,  
"query": {  
"bool": {  
"must": [  
{  
"query\_string": {  
"analyze\_wildcard": true,  
"query": "flowType:IPV6"  
}  
}  
]  
}  
},  
"aggs": {  
"byFlow": {  
"terms": {  
"script": "['trailer', doc.dstIp.value].join(',')",  
"order": {  
"\_term": "asc"  
},  
"size": 25  
}  
}  
}  
}

Results:  
"key" : "trailer,2001:0:15:15:15::",  
"key" : "trailer,2001:0:15:15:15::1",  
"key" : "trailer,2001:0:15:15:15::2",  
"key" : "trailer,2001:0:15:15:15::3",  
"key" : "trailer,2001:15:15:15::",  
"key" : "trailer,2001:15:15:15::1",  
"key" : "trailer,2001:15:15:15::2",  
"key" : "trailer,2001:15:15:15::3",  
"key" : "trailer,2001::15:15:15:0", \>\>\>\> This IP is lowest, but this not coming in the first????  
"key" : "trailer,2001::15:15:15:1",  
"key" : "trailer,2001::15:15:15:2",  
"key" : "trailer,2001::15:15:15:3",  
"key" : "trailer,2001::15:15:15:4",  
"key" : "trailer,3001:0:12:12:12::",  
"key" : "trailer,3001:0:12:12:12::1",  
"key" : "trailer,3001:0:12:12:12::2",  
"key" : "trailer,3001:0:12:12:12::3",  
"key" : "trailer,3001:12:12:12::",  
"key" : "trailer,3001:12:12:12::1",  
"key" : "trailer,3001:12:12:12::2",  
"key" : "trailer,3001:12:12:12::3",

---

<div class="post-metadata">

**Author:** ![singamsundeep](https://avatars.discourse-cdn.com/v4/letter/s/e36b37/32.png) [@singamsundeep](https://discuss.elastic.co/u/singamsundeep)\
**Post date:** [October 30, 2019, 4:59am UTC](https://discuss.elastic.co/t/sorting-for-ip-ipv4-ipv6/205361/3 "2019-10-30T04:59:05Z")

</div>

Noticed simple sort is working for IPv6 but order doesn't seems to be working.

PUT my\_index3  
{  
"mappings": {  
"properties": {  
"srcIpv6": { "type": "ip"}  
}  
}  
}

Not Working: (Output is not properly sorted)  
GET my\_index3/\_search  
{  
"aggs": {  
"byFlow": {  
"terms": {  
"script": "[doc.srcIpv6.value].join(',')",  
"order": {  
"\_key": "asc"  
},  
"size": 25  
}  
}  
}  
}

Working:  
GET /my\_index3/\_search  
{  
"sort" : [{ "srcIpv6" : {"order" : "asc"}}],  
"size": "40"  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 27, 2019, 5:05am UTC](https://discuss.elastic.co/t/sorting-for-ip-ipv4-ipv6/205361/4 "2019-11-27T05:05:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
