Visualization - Group IP Addresses by /24 Subnet

Happy in using Elastic Stack 5 with Ingest mode (Filebeat) now :slight_smile:

I have a visualization (Data Table) to show all the source IP count to visit my web server.

clientip: Ascending Count 1000 1000 500 200 30 10

How can I group them by /24 subnet to become the list like below?

clientip: Ascending Count 2000 1000 30 10

Elasticsearch allows you to create aggregation buckets, including using a CIDR mask but it doesn't appear you can do it automatically. You might be able to create a custom tokenizer to accomplish this.

