Overview

format_ipv4_mask

You can use format_ipv4_mask to normalize IP addresses, extract network segments, or apply filtering or grouping logic based on subnet granularity.

Usage#

Syntax#

format_ipv4_mask(ip, prefix)

Parameters#

Name Type Required Description
ip string ✓ The IPv4 address in CIDR notation. You can use a string (for example, '192.168.1.1') or a big-endian number.
prefix int ✓ An integer between 0 and 32. Specifies how many leading bits to include in the mask.

Returns#

A string representing the IPv4 address in CIDR notation if the conversion succeeds. If the conversion fails, the function returns an empty string.

Example#

Query

['sample-http-logs']
| extend subnet = format_ipv4_mask('192.168.1.54', 24)
| project _time, subnet

Run in Playground

Output

_time subnet
1Jun 30, 11:11:46 192.168.1.0/24
  • format_ipv4: Converts a 32-bit unsigned integer to an IPv4 address string. Use it when your input is a raw numeric IP instead of a prefix length.
  • parse_ipv4: Parses an IPv4 string into a numeric representation. Use it when you want to do arithmetic or masking on IP addresses.
  • ipv4_is_in_range: Checks whether an IPv4 address falls within a given range. Use it when you need to filter or classify IPs against subnets.

Other query languages#

Splunk SPL users

SPL doesn’t have a direct built-in equivalent to format_ipv4_mask. To format IPv4 addresses with subnet masks, you typically use custom field extractions or external lookup tables. In contrast, APL provides a native function for this task, simplifying analysis at the network or subnet level.

Splunk example

| eval cidr=ip."/24"

APL equivalent

format_ipv4_mask('192.168.1.10', 24)
ANSI SQL users

Standard SQL lacks native functions for manipulating IP addresses or CIDR notation. This type of transformation usually requires application-side logic or user-defined functions (UDFs). APL simplifies this by offering a first-class function for formatting IPs directly in queries.

SQL example

-- Requires custom UDF or external processing
SELECT format_ip_with_mask(ip, 24) FROM connections

APL equivalent

format_ipv4_mask(ip, 24)

Updated

Was this page helpful?