# Add a tag to IP addresses in alerts

**URL:** <https://forum.suricata.io/t/add-a-tag-to-ip-addresses-in-alerts/3752>\
**Category:** Rules\
**Tags:** configuration\
**Created:** [July 27, 2023, 11:23am UTC](https://forum.suricata.io/t/add-a-tag-to-ip-addresses-in-alerts/3752 "2023-07-27T11:23:33Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![lukashino](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/lukashino/32/1150_2.png) [@lukashino](https://forum.suricata.io/u/lukashino)\
**Post date:** [July 27, 2023, 11:23am UTC](https://forum.suricata.io/t/add-a-tag-to-ip-addresses-in-alerts/3752/1 "2023-07-27T11:23:33Z")

</div>

Hi all,

Considering I have a list of IP addresses in variables (e.g. HTTP\_SERVERS: “[192.168.128.0/24]”, SMTP\_SERVERS: “[192.168.10.0/24]”) and a ruleset with a rule e.g.  
`alert ip any any -> any any (msg: "test"; sid: 1;)`

Is it possible to include a tag or some kind of information that would tell which variable(s) fit the IP addresses?

So that an alert would contain information something like:  
`192.168.10.32 (SMTP_SERVERS) -> 57.43.7.32 (unknown) "test"`

Thanks.
