# Tagging for public IP address

**URL:** <https://discuss.elastic.co/t/tagging-for-public-ip-address/183433>\
**Category:** Logstash\
**Created:** [May 29, 2019, 11:38pm UTC](https://discuss.elastic.co/t/tagging-for-public-ip-address/183433 "2019-05-29T23:38:28Z")\
**Posts on this page:** 1\
**Showing post:** 8

<div class="post-metadata">

**Author:** ![psmaan1](https://avatars.discourse-cdn.com/v4/letter/p/c6cbf5/32.png) [@psmaan1](https://discuss.elastic.co/u/psmaan1)\
**Post date:** [May 31, 2019, 4:11pm UTC](https://discuss.elastic.co/t/tagging-for-public-ip-address/183433/8 "2019-05-31T16:11:42Z")

</div>

Hey Badger,  
Following your advice, I tried to do it using cidr. I end up combining both approaches.  
Here is how the solution looks like now:

filter {  
if [winlog][task] == "Logon" {  
cidr{  
add\_tag =\> ["src\_private"]  
address =\> ["%{[winlog][event\_data][IpAddress]}" ]  
network =\> ["10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16", "127.0.0.0/8"] }

if [winlog][event\_data][IpAddress] =~ /^\b(?:\d{1,3}.){3}\d{1,3}\b/ and "src\_private" not in [tags] {  
if [winlog][event\_data][IpAddress] !~ /^(0.0.0.0)/ {  
mutate { add\_tag =\> "src\_public" }  
} }  
}  
}

However, I am getting lot of " Invalid IP Address, skipping \*\*" logs in logstash log file from cidr. I believe these are those entries which does not have a valid IP e.g. Null IP, ::1 etc.

Is there any way I can get rid of these, as this would fill up my logs files and disk space.

---

_[View the full topic](https://discuss.elastic.co/t/tagging-for-public-ip-address/183433)._
