# Anonymize IPv4 address

**URL:** <https://community.graylog.org/t/anonymize-ipv4-address/20685>\
**Category:** Pipeline Rules\
**Tags:** pipeline-rules\
**Created:** [July 29, 2021, 1:38pm UTC](https://community.graylog.org/t/anonymize-ipv4-address/20685 "2021-07-29T13:38:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [July 29, 2021, 1:38pm UTC](https://community.graylog.org/t/anonymize-ipv4-address/20685/1 "2021-07-29T13:38:21Z")

</div>

Sometimes you need to anonymize IPv4 address. There are lot of solutions, one simple is to replace last octet with some text. This little snippet uses this approach to replace all ipv4 address in message:

```auto
rule "Anonymize IPv4"
when
   has_field("message")
then
      let anon_ip = regex_replace(pattern: "(?<![0-9])(?:([0-1]?[0-9]{1,2}|2[0-4][0-9]|25[0-5])[.]([0-1]?[0-9]{1,2}|2[0-4][0-9]|25[0-5])[.]([0-1]?[0-9]{1,2}|2[0-4][0-9]|25[0-5])[.]([0-1]?[0-9]{1,2}|2[0-4][0-9]|25[0-5]))(?![0-9])",
        value: to_string($message.message),
        replacement: "$1.$2.$3.xxx"
    );
    set_field("message", anon_ip);
end

```

---

<div class="post-metadata">

**Author:** ![dscryber](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/dscryber/32/14178_2.png) [@dscryber](https://community.graylog.org/u/dscryber)\
**Post date:** [July 29, 2021, 3:32pm UTC](https://community.graylog.org/t/anonymize-ipv4-address/20685/2 "2021-07-29T15:32:19Z")

</div>

Thanks for the first post, @shoothub . Let us know if we need to add anything to this category

---

<div class="post-metadata">

**Author:** ![Linedo](https://avatars.discourse-cdn.com/v4/letter/l/c89c15/32.png) [@Linedo](https://community.graylog.org/u/Linedo)\
**Post date:** [January 27, 2023, 5:18pm UTC](https://community.graylog.org/t/anonymize-ipv4-address/20685/3 "2023-01-27T17:18:58Z")

</div>

Hey @shoothub, great post! (even if it was 2 years ago) Really helped me with syntax.

Although for recognizing IPv4 addresses with a regex pattern a simpler alternative would be:

```auto
let anon_ip = regex_replace(pattern: "(\\d{1,3}\\.)(\\d{1,3}\\.)(\\d{1,3}\\.)(\\d{1,3})",
value: to_string($message.message), 
replacement: "$1$2$3X"
);

```

PS: Don’t forget to use double escapes in pipelines, this has caught me out multiple times

---

<div class="post-metadata">

**Author:** ![dscryber](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/dscryber/32/14178_2.png) [@dscryber](https://community.graylog.org/u/dscryber)\
**Post date:** [January 28, 2023, 12:55am UTC](https://community.graylog.org/t/anonymize-ipv4-address/20685/4 "2023-01-28T00:55:11Z")

</div>

@Linedo Thanks for reviving a member’s “blast from the past!” Yes, those of us who have been hanging out in this community of a few years now know of the legendary @shoothub . He contributed several gems of awesome help. We haven’t seen him the community for some time now, but @shoothub , thanks for your contributions, and if you’re still out there, stop by again. The Open Community misses you! 🙂
