Firewall - Content - Address list

Greetings! If an l2tp authorization error occurs, a message of the following type appears in the logs:

peer failed to authorize: IKEv2-peer 111.111.11.11[4500]-222.222.22.22[4500] spi:19545suoihda123uis

Is it possible to somehow add in adress-list peer’s ip 222.222.22.22.

I 'm looking towards Firewall - Advanced - Content
But I can’t figure out how to set values.

Search the forum, there are dozens of scripts that read the IPs from the logs and save them in a list in the firewall.

http://forum.mikrotik.com/t/black-list-for-failed-login-to-ipsec-vpn/130090/1