Overview

ipv4_is_private

This function is especially useful in scenarios where you want to:

  • Exclude private IPs from logs to focus on public traffic.
  • Identify traffic originating from within an internal network.
  • Simplify security analysis by categorizing IP addresses.

The private IPv4 addresses reserved for private networks by the Internet Assigned Numbers Authority (IANA) are the following:

IP address range Number of addresses Largest CIDR block (subnet mask)
10.0.0.0 – 10.255.255.255 16777216 10.0.0.0/8 (255.0.0.0)
172.16.0.0 – 172.31.255.255 1048576 172.16.0.0/12 (255.240.0.0)
192.168.0.0 – 192.168.255.255 65536 192.168.0.0/16 (255.255.0.0)

Usage#

Syntax#

ipv4_is_private(ip: string)

Parameters#

Parameter Type Description
ip string The IPv4 address to evaluate for private range status.

Returns#

  • true: The input IP address is private.
  • false: The input IP address isn’t private.

Use case example#

You can use ipv4_is_private to filter logs and focus on public traffic for external analysis.

Query

['sample-http-logs']
| extend is_private = ipv4_is_private('192.168.0.1')

Run in Playground

Output

geo.country is_private
USA true
UK true
  • ipv4_compare: Compares two IPv4 addresses lexicographically. Use for sorting or range evaluations.
  • ipv4_is_in_range: Checks if an IP address is within a specified range.
  • parse_ipv4: Converts a dotted-decimal IP address into a numeric representation.

Other query languages#

Splunk SPL users

In Splunk SPL, you might use a combination of CIDR matching functions or regex to check for private IPs. In APL, the ipv4_is_private function offers a built-in and concise way to achieve the same result.

Splunk example

eval is_private=if(cidrmatch("10.0.0.0/8", ip) OR cidrmatch("172.16.0.0/12", ip) OR cidrmatch("192.168.0.0/16", ip), 1, 0)

APL equivalent

['sample-http-logs']
| extend is_private=ipv4_is_private(client_ip)
ANSI SQL users

In ANSI SQL, you might use CASE statements with CIDR-based checks or regex patterns to detect private IPs. In APL, the ipv4_is_private function simplifies this with a single call.

SQL example

SELECT ip,
       CASE
         WHEN ip LIKE '10.%' OR ip LIKE '172.16.%' OR ip LIKE '192.168.%' THEN 'true'
         ELSE 'false'
       END AS is_private
FROM logs;

APL equivalent

['sample-http-logs']
| extend is_private=ipv4_is_private(client_ip)

Updated

Was this page helpful?