ipv6_is_in_range
You can use this function when analyzing HTTP logs, trace telemetry, or security events where IPv6 addresses are present, and you want to restrict attention to or exclude certain address ranges.
Usage#
Syntax#
ipv6_is_in_range(ipv6: string, cidr_range: string)Parameters#
| Name | Type | Description |
|---|---|---|
ipv6 |
string | The IPv6 address to check. |
cidr_range |
string | The IPv6 CIDR block (e.g. '2001:db8::/32'). |
Returns#
A bool value:
trueif the IPv6 address is within the specified CIDR range.falseotherwise.
Example#
Use this function to isolate internal service calls originating from a designated IPv6 block.
Query
['otel-demo-traces']
| extend inRange = ipv6_is_in_range('fd00::a1b2', 'fd00::/8')
| project _time, span_id, ['service.name'], duration, inRangeOutput
| _time | span_id | ['service.name'] | duration | inRange |
|---|---|---|---|---|
| 2025-06-28T11:20:00Z | span-124 | frontend | 00:00:02.4 | true |
| 2025-06-28T11:21:03Z | span-209 | cartservice | 00:00:01.1 | true |
List of related functions#
- ipv4_is_in_range: Checks whether an IPv4 address is within a specified CIDR range. Use this function when working with IPv4 instead of IPv6.
- ipv6_compare: Compares two IPv6 addresses. Use when you want to sort or test address equality or ordering.
- ipv6_is_match: Checks whether an IPv6 address matches a pattern. Use for wildcard or partial-match filtering rather than range checking.
Other query languages#
Splunk SPL users
In Splunk SPL, IP range checking for IPv6 addresses typically requires custom scripts or manual logic, as there is no built-in function equivalent to ipv6_is_in_range.
Splunk example
| eval inRange=if(cidrmatch("2001:db8::/32", src_ip), "yes", "no")APL equivalent
['sample-http-logs']
| extend inRange = ipv6_is_in_range(src_ip, '2001:db8::/32')ANSI SQL users
ANSI SQL doesn’t have native functions for CIDR range checks on IPv6 addresses. You typically rely on user-defined functions (UDFs) or external tooling. In APL, ipv6_is_in_range provides this capability out of the box.
SQL example
-- Using a hypothetical UDF
SELECT ipv6_in_range(ip_address, '2001:db8::/32') AS in_range FROM logs;APL equivalent
['sample-http-logs']
| extend inRange = ipv6_is_in_range(src_ip, '2001:db8::/32')