ipv4_is_in_any_range
This function is particularly helpful for security monitoring, analyzing log data for specific geolocated traffic, or validating access based on allowed IP ranges.
Usage#
Syntax#
ipv4_is_in_any_range(ip_address: string, ranges: dynamic)Parameters#
| Parameter | Type | Description |
|---|---|---|
ip_address |
string | The IPv4 address to evaluate. |
ranges |
dynamic | A list of IPv4 ranges or CIDR blocks to check against (in JSON array form). |
Returns#
trueif the IP address is in any specified range.falseotherwise.nullif the conversion of a string wasn’t successful.
Use case example#
Identify log entries from specific subnets, such as local office IP ranges.
Query
['sample-http-logs']
| extend is_in_range = ipv4_is_in_any_range('192.168.0.0', dynamic(['192.168.0.0/24', '10.0.0.0/8']))Output
| _time | id | method | uri | status | is_in_range |
|---|---|---|---|---|---|
| 2024-11-14 10:00:00 | user123 | GET | /home | 200 | true |
List of related functions#
- ipv4_compare: Compares two IPv4 addresses lexicographically. Use for sorting or range evaluations.
- ipv4_is_in_range: Checks if an IP address is within a specified range.
- ipv4_is_private: Checks if an IPv4 address is within private IP ranges.
- parse_ipv4: Converts a dotted-decimal IP address into a numeric representation.
Other query languages#
Splunk SPL users
In Splunk SPL, you use cidrmatch to check if an IP belongs to a range. In APL, ipv4_is_in_any_range is equivalent, but it supports evaluating against multiple ranges simultaneously.
Splunk example
| eval is_in_range = cidrmatch("192.168.0.0/24", ip_address)APL equivalent
['dataset']
| extend is_in_range = ipv4_is_in_any_range(ip_address, dynamic(['192.168.0.0/24', '10.0.0.0/8']))ANSI SQL users
ANSI SQL doesn’t have a built-in function for checking IP ranges. Instead, you use custom functions or comparisons. APL’s ipv4_is_in_any_range simplifies this by handling multiple CIDR blocks and ranges in a single function.
SQL example
SELECT *,
CASE WHEN ip_address BETWEEN '192.168.0.0' AND '192.168.0.255' THEN 1 ELSE 0 END AS is_in_range
FROM dataset;APL equivalent
['dataset']
| extend is_in_range = ipv4_is_in_any_range(ip_address, dynamic(['192.168.0.0/24', '10.0.0.0/8']))