{"id":28,"date":"2026-08-16T05:19:40","date_gmt":"2026-08-16T05:19:40","guid":{"rendered":"https:\/\/easyextract.online\/blog\/?p=28"},"modified":"2026-08-16T09:04:45","modified_gmt":"2026-08-16T09:04:45","slug":"ipv4-vs-ipv6-in-log-files","status":"publish","type":"post","link":"https:\/\/easyextract.online\/blog\/ipv4-vs-ipv6-in-log-files\/","title":{"rendered":"IPv4 vs IPv6 in Log Files: How to Tell Them Apart and Extract Them"},"content":{"rendered":"<p><strong>In a log file, an IPv4 address looks like <code>203.0.113.45<\/code> \u2014 four numbers separated by dots \u2014 while an IPv6 address looks like <code>2001:db8::1<\/code> \u2014 groups of hex separated by colons, often shortened with a double colon.<\/strong> Modern servers log both in the same file, which is exactly why pulling clean IP addresses out of logs is fiddlier than it looks. Here&#8217;s how to tell them apart and extract them reliably.<\/p>\n<h2>The two formats at a glance<\/h2>\n<table>\n<thead>\n<tr>\n<th><\/th>\n<th>IPv4<\/th>\n<th>IPv6<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Example<\/td>\n<td><code>203.0.113.45<\/code><\/td>\n<td><code>2001:0db8:0000:0000:0000:0000:0000:0001<\/code><\/td>\n<\/tr>\n<tr>\n<td>Shortened<\/td>\n<td>\u2014<\/td>\n<td><code>2001:db8::1<\/code><\/td>\n<\/tr>\n<tr>\n<td>Separator<\/td>\n<td>Dots<\/td>\n<td>Colons<\/td>\n<\/tr>\n<tr>\n<td>Digits<\/td>\n<td>Decimal (0\u2013255 per part)<\/td>\n<td>Hexadecimal (0\u2013ffff per group)<\/td>\n<\/tr>\n<tr>\n<td>Length<\/td>\n<td>32-bit (4 parts)<\/td>\n<td>128-bit (8 groups)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Why both show up in one log<\/h2>\n<p>A server reachable over IPv6 will log IPv6 client addresses; the same server still serves IPv4 clients and logs those too. You&#8217;ll also see IPv4-mapped IPv6 addresses like <code>::ffff:203.0.113.45<\/code>, and IPv6 link-local addresses carrying a scope such as <code>fe80::1%eth0<\/code>. One access log can contain all of these, mixed line by line.<\/p>\n<h2>Why extracting them is harder than it looks<\/h2>\n<p>The trap is that a pattern loose enough to match every IP address also matches things that aren&#8217;t addresses:<\/p>\n<ul>\n<li><strong>Version numbers and dates<\/strong> take the same shape as IPv4 \u2014 <code>1.2.3.4<\/code> from a changelog, <code>10.15.7<\/code> from a version string.<\/li>\n<li><strong>Impossible octets.<\/strong> <code>999.1.1.1<\/code> matches a naive pattern but is not a valid address \u2014 each IPv4 octet must be 0\u2013255.<\/li>\n<li><strong>Leading zeros.<\/strong> <code>192.168.01.1<\/code> is not valid and is almost always a version number.<\/li>\n<li><strong>IPv6 compression.<\/strong> The <code>::<\/code> shorthand means the same address can be written many ways, and hex groups can be mistaken for other identifiers.<\/li>\n<\/ul>\n<p>A good extractor range-checks every octet, rejects leading zeros, and understands compressed IPv6 \u2014 so you get real addresses, not version strings.<\/p>\n<h2>How to pull the IP addresses out of a log<\/h2>\n<p>Paste the log into the <a href=\"https:\/\/easyextract.online\/ip-address-extractor\/\">IP address extractor<\/a>: it matches both IPv4 and IPv6, validates every match, removes duplicates, sorts them, and labels each as public, private, loopback or reserved \u2014 which is usually the question that matters, &#8220;which of these are actually external?&#8221; It runs entirely in your browser, so the log is never uploaded. That&#8217;s important, because a single access-log line can carry a session token, an internal hostname and a customer&#8217;s IP address \u2014 all personal data under the GDPR.<\/p>\n<p>Logs rarely contain only IP addresses. To pull the hardware addresses out of the same file, use the <a href=\"https:\/\/easyextract.online\/mac-address-extractor\/\">MAC address extractor<\/a>; for the hashes and checksums in a security log, the <a href=\"https:\/\/easyextract.online\/hash-extractor\/\">hash extractor<\/a>.<\/p>\n<h2>Frequently asked questions<\/h2>\n<p><strong>How do I extract all IP addresses from a log file?<\/strong><br \/>\nPaste the log into a browser-based <a href=\"https:\/\/easyextract.online\/ip-address-extractor\/\">IP address extractor<\/a> and it lists every valid IPv4 and IPv6 address, deduplicated and labelled public or private. Nothing is uploaded.<\/p>\n<p><strong>How do I tell an IPv4 address from an IPv6 address?<\/strong><br \/>\nIPv4 uses four decimal numbers separated by dots (<code>203.0.113.45<\/code>); IPv6 uses groups of hexadecimal separated by colons, often shortened with a double colon (<code>2001:db8::1<\/code>).<\/p>\n<p><strong>Why does my regex match version numbers as IP addresses?<\/strong><br \/>\nBecause a version like <code>1.2.3.4<\/code> has the same shape as an IPv4 address. A proper extractor range-checks each octet (0\u2013255) and rejects leading zeros, which filters version strings out.<\/p>\n<p><strong>What is an IPv4-mapped IPv6 address?<\/strong><br \/>\nAn address like <code>::ffff:203.0.113.45<\/code> that represents an IPv4 address inside the IPv6 format \u2014 common when a dual-stack server logs an IPv4 client over an IPv6 socket.<\/p>\n<h2>Related reading<\/h2>\n<ul>\n<li><a href=\"https:\/\/easyextract.online\/blog\/what-is-data-extraction\/\">What is data extraction?<\/a><\/li>\n<li><a href=\"https:\/\/easyextract.online\/blog\/are-online-file-converters-safe\/\">Are online file converters safe?<\/a><\/li>\n<\/ul>\n<p><em>Last updated: 16 August 2026.<\/em><\/p>\n<p><script type=\"application\/ld+json\">\n{\"@context\":\"https:\/\/schema.org\",\"@type\":\"FAQPage\",\"mainEntity\":[\n{\"@type\":\"Question\",\"name\":\"How do I extract all IP addresses from a log file?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Paste the log into a browser-based IP address extractor and it lists every valid IPv4 and IPv6 address, deduplicated and labelled public or private. Nothing is uploaded.\"}},\n{\"@type\":\"Question\",\"name\":\"How do I tell an IPv4 address from an IPv6 address?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"IPv4 uses four decimal numbers separated by dots (203.0.113.45); IPv6 uses groups of hexadecimal separated by colons, often shortened with a double colon (2001:db8::1).\"}},\n{\"@type\":\"Question\",\"name\":\"Why does my regex match version numbers as IP addresses?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"A version like 1.2.3.4 has the same shape as an IPv4 address. A proper extractor range-checks each octet (0-255) and rejects leading zeros, which filters version strings out.\"}},\n{\"@type\":\"Question\",\"name\":\"What is an IPv4-mapped IPv6 address?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"An address like ::ffff:203.0.113.45 that represents an IPv4 address inside the IPv6 format \u2014 common when a dual-stack server logs an IPv4 client over an IPv6 socket.\"}}\n]}<\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In a log file, an IPv4 address looks like 203.0.113.45 \u2014 four numbers separated by dots \u2014 while an IPv6 address looks like 2001:db8::1 \u2014 groups of hex separated by colons, often shortened with\u2026<\/p>\n","protected":false},"author":1,"featured_media":40,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"slim_seo":{"title":"IPv4 vs IPv6 in Log Files: How to Tell Them Apart and Extract Them - EasyExtract","description":"In a log file, an IPv4 address looks like 203.0.113.45 \u2014 four numbers separated by dots \u2014 while an IPv6 address looks like 2001:db8::1 \u2014 groups of hex separated"},"footnotes":""},"categories":[3],"tags":[],"class_list":["post-28","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-guides"],"_links":{"self":[{"href":"https:\/\/easyextract.online\/blog\/wp-json\/wp\/v2\/posts\/28","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/easyextract.online\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/easyextract.online\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/easyextract.online\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/easyextract.online\/blog\/wp-json\/wp\/v2\/comments?post=28"}],"version-history":[{"count":1,"href":"https:\/\/easyextract.online\/blog\/wp-json\/wp\/v2\/posts\/28\/revisions"}],"predecessor-version":[{"id":31,"href":"https:\/\/easyextract.online\/blog\/wp-json\/wp\/v2\/posts\/28\/revisions\/31"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/easyextract.online\/blog\/wp-json\/wp\/v2\/media\/40"}],"wp:attachment":[{"href":"https:\/\/easyextract.online\/blog\/wp-json\/wp\/v2\/media?parent=28"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/easyextract.online\/blog\/wp-json\/wp\/v2\/categories?post=28"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/easyextract.online\/blog\/wp-json\/wp\/v2\/tags?post=28"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}