format_ipv4_mask
You can use format_ipv4_mask to normalize IP addresses, extract network segments, or apply filtering or grouping logic based on subnet granularity.
Usage#
Syntax#
format_ipv4_mask(ip, prefix)Parameters#
| Name | Type | Required | Description |
|---|---|---|---|
| ip | string | ✓ | The IPv4 address in CIDR notation. You can use a string (for example, '192.168.1.1') or a big-endian number. |
| prefix | int | ✓ | An integer between 0 and 32. Specifies how many leading bits to include in the mask. |
Returns#
A string representing the IPv4 address in CIDR notation if the conversion succeeds. If the conversion fails, the function returns an empty string.
Example#
Query
['sample-http-logs']
| extend subnet = format_ipv4_mask('192.168.1.54', 24)
| project _time, subnetOutput
| _time | subnet |
|---|---|
| 1Jun 30, 11:11:46 | 192.168.1.0/24 |
List of related functions#
- format_ipv4: Converts a 32-bit unsigned integer to an IPv4 address string. Use it when your input is a raw numeric IP instead of a prefix length.
- parse_ipv4: Parses an IPv4 string into a numeric representation. Use it when you want to do arithmetic or masking on IP addresses.
- ipv4_is_in_range: Checks whether an IPv4 address falls within a given range. Use it when you need to filter or classify IPs against subnets.
Other query languages#
Splunk SPL users
SPL doesn’t have a direct built-in equivalent to format_ipv4_mask. To format IPv4 addresses with subnet masks, you typically use custom field extractions or external lookup tables. In contrast, APL provides a native function for this task, simplifying analysis at the network or subnet level.
Splunk example
| eval cidr=ip."/24"APL equivalent
format_ipv4_mask('192.168.1.10', 24)ANSI SQL users
Standard SQL lacks native functions for manipulating IP addresses or CIDR notation. This type of transformation usually requires application-side logic or user-defined functions (UDFs). APL simplifies this by offering a first-class function for formatting IPs directly in queries.
SQL example
-- Requires custom UDF or external processing
SELECT format_ip_with_mask(ip, 24) FROM connectionsAPL equivalent
format_ipv4_mask(ip, 24)