ipv4_is_in_range
You can use this function to:
- Analyze logs for requests originating from specific IP address ranges.
- Detect unauthorized or suspicious activity by isolating traffic outside trusted IP ranges.
- Aggregate metrics for specific IP blocks or subnets.
Usage#
Syntax#
ipv4_is_in_range(ip: string, range: string)Parameters#
| Parameter | Type | Description |
|---|---|---|
ip |
string | The IPv4 address to evaluate. |
range |
string | The IPv4 range in CIDR notation (for example, 192.168.1.0/24). |
Returns#
trueif the IPv4 address is in the range.falseotherwise.nullif the conversion of a string wasn’t successful.
Use case example#
You can use ipv4_is_in_range to identify traffic from specific geographic regions or service provider IP blocks.
Query
['sample-http-logs']
| extend in_range = ipv4_is_in_range('192.168.1.0', '192.168.1.0/24')Output
| geo.city | in_range |
|---|---|
| Seattle | true |
| Denver | true |
This query identifies the number of requests from IP addresses in the specified range.
List of related functions#
- ipv4_compare: Compares two IPv4 addresses lexicographically. Use for sorting or range evaluations.
- ipv4_is_private: Checks if an IPv4 address is within private IP ranges.
- parse_ipv4: Converts a dotted-decimal IP address into a numeric representation.
Other query languages#
Splunk SPL users
The ipv4_is_in_range function in APL operates similarly to the cidrmatch function in Splunk SPL. Both determine whether an IP address belongs to a specified range, but APL uses a different syntax and format.
Splunk example
| eval in_range = cidrmatch("192.168.0.0/24", ip_address)APL equivalent
['sample-http-logs']
| extend in_range = ipv4_is_in_range(ip_address, '192.168.0.0/24')ANSI SQL users
ANSI SQL doesn’t have a built-in equivalent for determining if an IP address belongs to a CIDR range. In SQL, you would typically need custom functions or expressions to achieve this. APL’s ipv4_is_in_range provides a concise way to perform this operation.
SQL example
SELECT CASE
WHEN ip_address BETWEEN '192.168.0.0' AND '192.168.0.255' THEN 1
ELSE 0
END AS in_range
FROM logsAPL equivalent
['sample-http-logs']
| extend in_range = ipv4_is_in_range(ip_address, '192.168.0.0/24')