Skip to content

Support ip_range in Enrichment  #59037

@srikwit

Description

@srikwit

Elasticsearch supports the ip_range type.

One way to reduce a lot of traffic from investigation or focus on a specific network is by the use of allow or deny lists.
Currently I am only able to enrich IP's individually as the enrich index converts them into a keyword.
As a subnet size increases, it is not effective to expand it and do an enrichment on a 1:1 basis.

Kindly consider for supporting ip_range as it will be helpful to reduce the size of an allow or deny list index and help quicker processing for a lot of security based use cases.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions