Try it free

DPL Network Data

  • Latest Dynatrace
  • Reference

Overview

IP (alias IPADDR) matches both IPv4 and IPv6 addresses, while IPV4 and IPV6 each match only their own family. The following table shows how the same inputs are parsed by each matcher—null means the input is not a valid address for that matcher.

Descriptioninput (string)IP (ip)IPV4 (ip)IPV6 (ip)

IPv4 address

192.168.33.1

192.168.33.1

192.168.33.1

null

IPv4 loopback

127.0.0.1

127.0.0.1

127.0.0.1

null

IPv6 address

2a00:1450:4010:c05::69

2a00:1450:4010:0c05::0069

null

2a00:1450:4010:0c05::0069

IPv6 loopback

::1

::0001

null

::0001

Dashes notation

192-168-33-1

null

null

null

Whitespace

␣

null

null

null

See how to use in DQL
data record(input = "192.168.33.1"),
record(input = "127.0.0.1"),
record(input = "2a00:1450:4010:c05::69"),
record(input = "::1"),
record(input = "192-168-33-1"),
record(input = " ")
| parse input, "IP:ip"
| parse input, "IPV4:ipv4"
| parse input, "IPV6:ipv6"

IP, IPADDR

Matches IPv4 addresses in dot-decimal notation and IPv6 addresses in hextet notation.

IP—like IPV4 and IPV6—reads the longest valid leading portion of the address and stops at the first character that cannot extend it, ignoring the rest of the token. Some invalid or non-standard inputs are therefore truncated to a shorter valid address instead of returning null: for example, an octet above 255, more than four octets, or trailing non-digit characters. Leading zeros in an octet are stripped, and IPv6 inputs are normalized to lowercase with each hextet padded to four digits and the longest zero-run compressed to ::.

Use the following expression to parse IP addresses:

IP:result

For example, parsing IPv4 and IPv6 addresses and their edge cases:

Descriptioninput (string)result (ip)

IPv4 address

192.168.33.1

192.168.33.1

IPv6 address

1080:0:0:0:8:800:200C:417A

1080::0008:0800:200c:417a

Leading zero in octet

192.168.01.1

192.168.1.1

Over-range last octet

192.168.95.1002

192.168.95.100

Octet over 255

192.168.0.256

192.168.0.25

More than four octets

192.168.1.1.1

192.168.1.1

Trailing non-digit characters

192.168.1.2abc

192.168.1.2

Fewer than four octets

192.168.1

null

Over-range octet before a separator

999.999.999.999

null

Dashes notation

192-168-33-1

null

Invalid

not-an-ip

null

Whitespace

␣

null

See how to use in DQL
data record(input = "192.168.33.1"),
record(input = "1080:0:0:0:8:800:200C:417A"),
record(input = "192.168.01.1"),
record(input = "192.168.95.1002"),
record(input = "192.168.0.256"),
record(input = "192.168.1.1.1"),
record(input = "192.168.1.2abc"),
record(input = "192.168.1"),
record(input = "999.999.999.999"),
record(input = "192-168-33-1"),
record(input = "not-an-ip"),
record(input = " ")
| parse input, "IP:result"

Returns

The data type of the extracted value is ip.

Basic example

Example: Match a field that contains a valid IP address

Use the following expression to check whether the value is a valid IP address:

IP
input (string)result (boolean)

192.168.33.1

true

1080:0:0:0:8:800:200C:417A

true

192-168-33-1

false

not-an-ip

false

See how to use in DQL
data record(input = "192.168.33.1"),
record(input = "1080:0:0:0:8:800:200C:417A"),
record(input = "192-168-33-1"),
record(input = "not-an-ip")
| fieldsAdd result = matchesPattern(input, "IP")

Practical example

Example: Parse an IP address from records with variable endings

Given records that share a fixed structure at the beginning but have a variable tail, use the following expression to skip to the ip= field and extract the IP address regardless of what follows:

LD 'ip=' IP:ip
input (string)ip (ip)

userId=1246 ip=124.5.2.4

124.5.2.4

userId=441122 ip=75.52.12.1 status=error message='Login failed'

75.52.12.1

userId=753434 ip=4.4.3.2

4.4.3.2

See how to use in DQL
data record(input = "userId=1246 ip=124.5.2.4"),
record(input = "userId=441122 ip=75.52.12.1 status=error message='Login failed'"),
record(input = "userId=753434 ip=4.4.3.2")
| parse input, "LD 'ip=' IP:ip"

IPV4, IPV4ADDR

Matches IPv4 addresses in dot-decimal notation.

IPV4—like IP and IPV6—reads the longest valid leading portion of the address and stops at the first character that cannot extend it, ignoring the rest of the token. Some invalid or non-standard inputs are therefore truncated to a shorter valid address instead of returning null: for example, an octet above 255, more than four octets, or trailing non-digit characters. Leading zeros in an octet are stripped.

Use the following expression to parse IPv4 addresses:

IPV4:result

For example, parsing IPv4 addresses:

Descriptioninput (string)result (ip)

IPv4 address

192.168.33.1

192.168.33.1

IPv4 loopback

127.0.0.1

127.0.0.1

Leading zero in octet

192.168.01.1

192.168.1.1

Over-range last octet

192.168.95.1002

192.168.95.100

Octet over 255

192.168.0.256

192.168.0.25

More than four octets

192.168.1.1.1

192.168.1.1

Trailing non-digit characters

192.168.1.2abc

192.168.1.2

Fewer than four octets

192.168.1

null

Over-range octet before a separator

999.999.999.999

null

IPv6 address

::1

null

Dashes notation

192-168-33-1

null

Whitespace

␣

null

See how to use in DQL
data record(input = "192.168.33.1"),
record(input = "127.0.0.1"),
record(input = "192.168.01.1"),
record(input = "192.168.95.1002"),
record(input = "192.168.0.256"),
record(input = "192.168.1.1.1"),
record(input = "192.168.1.2abc"),
record(input = "192.168.1"),
record(input = "999.999.999.999"),
record(input = "::1"),
record(input = "192-168-33-1"),
record(input = " ")
| parse input, "IPV4:result"

Returns

The data type of the extracted value is ip.

Practical example

Example: Parse an IPv4 address from a record

Given the following input:

source=192.168.33.1

Use the following expression to extract the IPv4 address from the source= field:

'source=' IPV4:ip
ip (ip)

192.168.33.1

See how to use in DQL
data record(input = "source=192.168.33.1")
| parse input, "'source=' IPV4:ip"

IPV6, IPV6ADDR

Matches IPv6 addresses in hextet notation.

IPV6—like IP and IPV4—reads the longest valid leading portion of the address and stops at the first character that cannot extend it, ignoring the rest of the token. Some invalid or non-standard inputs are therefore truncated to a shorter valid address instead of returning null: for example, a second ::, more than eight groups, an invalid hex digit, or IPv4-mapped notation (where parsing stops at the first .).

Use the following expression to parse IPv6 addresses:

IPV6:result

For example, parsing IPv6 addresses in different notations:

Descriptioninput (string)result (ip)

Full notation

fe80:0:0:0:8e1:734c:9cca:6bc3

fe80::08e1:734c:9cca:6bc3

Loopback

::1

::0001

Already compressed

2a00:1450:4010:c05::69

2a00:1450:4010:0c05::0069

IPv4-mapped notation

::ffff:192.168.1.1

::ffff:0192

Two :: groups

fe80::1::2

fe80::0001

More than eight groups

fe80:0:0:0:0:0:0:0:1

fe80::0000

Invalid hex digit

2001:db8::g1

2001:0db8::0000

Hextet too long

12345::1

null

IPv4 address

192.168.33.1

null

Dashes notation

192-168-33-1

null

Whitespace

␣

null

See how to use in DQL
data record(input = "fe80:0:0:0:8e1:734c:9cca:6bc3"),
record(input = "::1"),
record(input = "2a00:1450:4010:c05::69"),
record(input = "::ffff:192.168.1.1"),
record(input = "fe80::1::2"),
record(input = "fe80:0:0:0:0:0:0:0:1"),
record(input = "2001:db8::g1"),
record(input = "12345::1"),
record(input = "192.168.33.1"),
record(input = "192-168-33-1"),
record(input = " ")
| parse input, "IPV6:result"

Returns

The data type of the extracted value is ip.

Practical example

Example: Parse an IPv6 address from a record

Given the following input:

peer fe80:0:0:0:8e1:734c:9cca:6bc3 disconnected

Use the following expression to extract the IPv6 address from between peer and disconnected:

'peer ' IPV6:ip ' disconnected'
ip (ip)

fe80::08e1:734c:9cca:6bc3

See how to use in DQL
data record(input = "peer fe80:0:0:0:8e1:734c:9cca:6bc3 disconnected")
| parse input, "'peer ' IPV6:ip ' disconnected'"
Related tags
Dynatrace Platform