Overview

ipv6_is_in_range

You can use this function when analyzing HTTP logs, trace telemetry, or security events where IPv6 addresses are present, and you want to restrict attention to or exclude certain address ranges.

Usage#

Syntax#

ipv6_is_in_range(ipv6: string, cidr_range: string)

Parameters#

Name Type Description
ipv6 string The IPv6 address to check.
cidr_range string The IPv6 CIDR block (e.g. '2001:db8::/32').

Returns#

A bool value:

  • true if the IPv6 address is within the specified CIDR range.
  • false otherwise.

Example#

Use this function to isolate internal service calls originating from a designated IPv6 block.

Query

['otel-demo-traces']
| extend inRange = ipv6_is_in_range('fd00::a1b2', 'fd00::/8')
| project _time, span_id, ['service.name'], duration, inRange

Run in Playground

Output

_time span_id ['service.name'] duration inRange
2025-06-28T11:20:00Z span-124 frontend 00:00:02.4 true
2025-06-28T11:21:03Z span-209 cartservice 00:00:01.1 true
  • ipv4_is_in_range: Checks whether an IPv4 address is within a specified CIDR range. Use this function when working with IPv4 instead of IPv6.
  • ipv6_compare: Compares two IPv6 addresses. Use when you want to sort or test address equality or ordering.
  • ipv6_is_match: Checks whether an IPv6 address matches a pattern. Use for wildcard or partial-match filtering rather than range checking.

Other query languages#

Splunk SPL users

In Splunk SPL, IP range checking for IPv6 addresses typically requires custom scripts or manual logic, as there is no built-in function equivalent to ipv6_is_in_range.

Splunk example

| eval inRange=if(cidrmatch("2001:db8::/32", src_ip), "yes", "no")

APL equivalent

['sample-http-logs']
| extend inRange = ipv6_is_in_range(src_ip, '2001:db8::/32')
ANSI SQL users

ANSI SQL doesn’t have native functions for CIDR range checks on IPv6 addresses. You typically rely on user-defined functions (UDFs) or external tooling. In APL, ipv6_is_in_range provides this capability out of the box.

SQL example

-- Using a hypothetical UDF
SELECT ipv6_in_range(ip_address, '2001:db8::/32') AS in_range FROM logs;

APL equivalent

['sample-http-logs']
| extend inRange = ipv6_is_in_range(src_ip, '2001:db8::/32')

Updated

Was this page helpful?