IP range aggregation

IP range aggregation #

A multi-bucket aggregation like range, but for IP addresses — buckets are CIDR masks or from/to IP bounds.

Example #

The demo dataset has no IP-typed field (hosts are names like web-01), so the bucket is structurally valid but empty:

On an ip field, each bucket counts the addresses inside its subnet.

Parameters for ip_range #

  • field
    (Required, string) IP-typed field you wish to aggregate.
  • ranges
    (Required, object array) Buckets as { "mask": "cidr" } or { "from": "ip", "to": "ip" }; key names a bucket.
Calendar September 26, 2026
Edit Edit this page