IP (alias IPADDR) matches both IPv4 and IPv6 addresses, while IPV4 and IPV6 each match only their own family. The following table shows how the same inputs are parsed by each matcher—null means the input is not a valid address for that matcher.
| Description | input (string) | IP (ip) | IPV4 (ip) | IPV6 (ip) |
|---|---|---|---|---|
IPv4 address |
|
|
|
|
IPv4 loopback |
|
|
|
|
IPv6 address |
|
|
|
|
IPv6 loopback |
|
|
|
|
Dashes notation |
|
|
|
|
Whitespace |
|
|
|
|
data record(input = "192.168.33.1"),record(input = "127.0.0.1"),record(input = "2a00:1450:4010:c05::69"),record(input = "::1"),record(input = "192-168-33-1"),record(input = " ")| parse input, "IP:ip"| parse input, "IPV4:ipv4"| parse input, "IPV6:ipv6"
Matches IPv4 addresses in dot-decimal notation and IPv6 addresses in hextet notation.
IP—like IPV4 and IPV6—reads the longest valid leading portion of the address and stops at the first character that cannot extend it, ignoring the rest of the token. Some invalid or non-standard inputs are therefore truncated to a shorter valid address instead of returning null: for example, an octet above 255, more than four octets, or trailing non-digit characters. Leading zeros in an octet are stripped, and IPv6 inputs are normalized to lowercase with each hextet padded to four digits and the longest zero-run compressed to ::.
Use the following expression to parse IP addresses:
IP:result
For example, parsing IPv4 and IPv6 addresses and their edge cases:
| Description | input (string) | result (ip) |
|---|---|---|
IPv4 address |
|
|
IPv6 address |
|
|
Leading zero in octet |
|
|
Over-range last octet |
|
|
Octet over 255 |
|
|
More than four octets |
|
|
Trailing non-digit characters |
|
|
Fewer than four octets |
|
|
Over-range octet before a separator |
|
|
Dashes notation |
|
|
Invalid |
|
|
Whitespace |
|
|
data record(input = "192.168.33.1"),record(input = "1080:0:0:0:8:800:200C:417A"),record(input = "192.168.01.1"),record(input = "192.168.95.1002"),record(input = "192.168.0.256"),record(input = "192.168.1.1.1"),record(input = "192.168.1.2abc"),record(input = "192.168.1"),record(input = "999.999.999.999"),record(input = "192-168-33-1"),record(input = "not-an-ip"),record(input = " ")| parse input, "IP:result"
The data type of the extracted value is ip.
Use the following expression to check whether the value is a valid IP address:
IP
input (string) | result (boolean) |
|---|---|
|
|
|
|
|
|
|
|
data record(input = "192.168.33.1"),record(input = "1080:0:0:0:8:800:200C:417A"),record(input = "192-168-33-1"),record(input = "not-an-ip")| fieldsAdd result = matchesPattern(input, "IP")
Given records that share a fixed structure at the beginning but have a variable tail, use the following expression to skip to the ip= field and extract the IP address regardless of what follows:
LD 'ip=' IP:ip
input (string) | ip (ip) |
|---|---|
|
|
|
|
|
|
data record(input = "userId=1246 ip=124.5.2.4"),record(input = "userId=441122 ip=75.52.12.1 status=error message='Login failed'"),record(input = "userId=753434 ip=4.4.3.2")| parse input, "LD 'ip=' IP:ip"
Matches IPv4 addresses in dot-decimal notation.
IPV4—like IP and IPV6—reads the longest valid leading portion of the address and stops at the first character that cannot extend it, ignoring the rest of the token. Some invalid or non-standard inputs are therefore truncated to a shorter valid address instead of returning null: for example, an octet above 255, more than four octets, or trailing non-digit characters. Leading zeros in an octet are stripped.
Use the following expression to parse IPv4 addresses:
IPV4:result
For example, parsing IPv4 addresses:
| Description | input (string) | result (ip) |
|---|---|---|
IPv4 address |
|
|
IPv4 loopback |
|
|
Leading zero in octet |
|
|
Over-range last octet |
|
|
Octet over 255 |
|
|
More than four octets |
|
|
Trailing non-digit characters |
|
|
Fewer than four octets |
|
|
Over-range octet before a separator |
|
|
IPv6 address |
|
|
Dashes notation |
|
|
Whitespace |
|
|
data record(input = "192.168.33.1"),record(input = "127.0.0.1"),record(input = "192.168.01.1"),record(input = "192.168.95.1002"),record(input = "192.168.0.256"),record(input = "192.168.1.1.1"),record(input = "192.168.1.2abc"),record(input = "192.168.1"),record(input = "999.999.999.999"),record(input = "::1"),record(input = "192-168-33-1"),record(input = " ")| parse input, "IPV4:result"
The data type of the extracted value is ip.
Given the following input:
source=192.168.33.1
Use the following expression to extract the IPv4 address from the source= field:
'source=' IPV4:ip
ip (ip) |
|---|
|
data record(input = "source=192.168.33.1")| parse input, "'source=' IPV4:ip"
Matches IPv6 addresses in hextet notation.
IPV6—like IP and IPV4—reads the longest valid leading portion of the address and stops at the first character that cannot extend it, ignoring the rest of the token. Some invalid or non-standard inputs are therefore truncated to a shorter valid address instead of returning null: for example, a second ::, more than eight groups, an invalid hex digit, or IPv4-mapped notation (where parsing stops at the first .).
Use the following expression to parse IPv6 addresses:
IPV6:result
For example, parsing IPv6 addresses in different notations:
| Description | input (string) | result (ip) |
|---|---|---|
Full notation |
|
|
Loopback |
|
|
Already compressed |
|
|
IPv4-mapped notation |
|
|
Two |
|
|
More than eight groups |
|
|
Invalid hex digit |
|
|
Hextet too long |
|
|
IPv4 address |
|
|
Dashes notation |
|
|
Whitespace |
|
|
data record(input = "fe80:0:0:0:8e1:734c:9cca:6bc3"),record(input = "::1"),record(input = "2a00:1450:4010:c05::69"),record(input = "::ffff:192.168.1.1"),record(input = "fe80::1::2"),record(input = "fe80:0:0:0:0:0:0:0:1"),record(input = "2001:db8::g1"),record(input = "12345::1"),record(input = "192.168.33.1"),record(input = "192-168-33-1"),record(input = " ")| parse input, "IPV6:result"
The data type of the extracted value is ip.
Given the following input:
peer fe80:0:0:0:8e1:734c:9cca:6bc3 disconnected
Use the following expression to extract the IPv6 address from between peer and disconnected:
'peer ' IPV6:ip ' disconnected'
ip (ip) |
|---|
|
data record(input = "peer fe80:0:0:0:8e1:734c:9cca:6bc3 disconnected")| parse input, "'peer ' IPV6:ip ' disconnected'"