# Store an IP range in ES

**URL:** <https://discuss.elastic.co/t/store-an-ip-range-in-es/57468>\
**Category:** Elasticsearch\
**Created:** [August 8, 2016, 11:35am UTC](https://discuss.elastic.co/t/store-an-ip-range-in-es/57468 "2016-08-08T11:35:11Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![finux](https://avatars.discourse-cdn.com/v4/letter/f/a9adbd/32.png) [@finux](https://discuss.elastic.co/u/finux)\
**Post date:** [August 8, 2016, 11:35am UTC](https://discuss.elastic.co/t/store-an-ip-range-in-es/57468/1 "2016-08-08T11:35:11Z")

</div>

SO i've tried to find an answer to this and i've had no luck in finding the answer. I want to store an IP range such as '5.10.89.104', '5.10.89.107' and then be able to search for data associated within the particular range. so lets say that if i search for 5.10.89.106 the document associated with that range will show up.

I can find a ton of stuff looking up a range but nothing about storing a range

---

<div class="post-metadata">

**Author:** ![DiscussBuster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/discussbuster/32/11042_2.png) [@DiscussBuster](https://discuss.elastic.co/u/DiscussBuster)\
**Post date:** [August 8, 2016, 6:41pm UTC](https://discuss.elastic.co/t/store-an-ip-range-in-es/57468/2 "2016-08-08T18:41:32Z")

</div>

Well, you _could_ create a range query with the IPs and register it in the .percolator on your index, then match the document with the single IP address against the registered queries.

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [August 9, 2016, 8:38am UTC](https://discuss.elastic.co/t/store-an-ip-range-in-es/57468/3 "2016-08-09T08:38:54Z")

</div>

There are some ongoing developments in Lucene about adding the ability to index ranges, which will probably get exposed in elasticsearch at some point: [https://issues.apache.org/jira/browse/LUCENE-7381](https://issues.apache.org/jira/browse/LUCENE-7381)

---

<div class="post-metadata">

**Author:** ![finux](https://avatars.discourse-cdn.com/v4/letter/f/a9adbd/32.png) [@finux](https://discuss.elastic.co/u/finux)\
**Post date:** [August 9, 2016, 11:09am UTC](https://discuss.elastic.co/t/store-an-ip-range-in-es/57468/4 "2016-08-09T11:09:56Z")

</div>

i didn't know anything about .percolator so i shall read up and see if that helps, thank you for your reply - very helpful 😃

---

<div class="post-metadata">

**Author:** ![rusty](https://avatars.discourse-cdn.com/v4/letter/r/f17d59/32.png) [@rusty](https://discuss.elastic.co/u/rusty)\
**Post date:** [August 9, 2016, 4:18pm UTC](https://discuss.elastic.co/t/store-an-ip-range-in-es/57468/5 "2016-08-09T16:18:48Z")

</div>

Hi! Why don't create two fields IP\_START and IP\_END to store start and end of range?  
In search query you can compare your IP with it (documentation say that IP stores as long internally so it easyly comparable like numbers).

Like: IP \>= IP\_START and IP\<= IP\_END  
[http://pastebin.com/yChG2z2w](http://pastebin.com/yChG2z2w)

---

<div class="post-metadata">

**Author:** ![finux](https://avatars.discourse-cdn.com/v4/letter/f/a9adbd/32.png) [@finux](https://discuss.elastic.co/u/finux)\
**Post date:** [August 10, 2016, 7:50am UTC](https://discuss.elastic.co/t/store-an-ip-range-in-es/57468/6 "2016-08-10T07:50:24Z")

</div>

thanks for you suggestion i'll have a look into it, not sure though that's quite what i'm looking for though

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:28pm UTC](https://discuss.elastic.co/t/store-an-ip-range-in-es/57468/7 "2017-07-05T22:28:52Z")

</div>


