logstash-filter-translate icon indicating copy to clipboard operation
logstash-filter-translate copied to clipboard

Feature request: ability to interpret lookup string as subnet

Open geertn444 opened this issue 6 years ago • 1 comments

Expand the functionality by not just matching on the lookup field:

"1.1.1.1"

but have the ability to define the lookup dictionary as "subnets" and interprete them likewise. Then do subnets lookups instead of simple matches:

"1.0.0.0/24":"D"

ie source field of "1.1.1.1", "1.1.1.2" etc will all match the lookup entry and return "D". As usual in networking, the highest specific match should be returned: "1.0.0.0/8":"A" "1.1.1.0/24":"B"

1.1.1.1 should return B Matches can be done lighning fast by binary AND masking of ip and mask and compare that to subnet.

geertn444 avatar Apr 28 '18 09:04 geertn444

My group would like to have this too.

lisaens avatar May 08 '20 17:05 lisaens