Why matching four numbers is not enough
The shape of an IPv4 address — four numbers separated by dots — is also the shape of a software
version, a build number and several date formats. A pattern that accepts 203.0.113.44 will
happily accept 1.2.3.4 from a changelog and 999.888.777.666 from nowhere at
all.
Three checks separate them. Each octet must be in the range 0–255, which removes impossible numbers.
Leading zeros are rejected, because 192.168.01.1 is not a valid address and is almost always
a version string. And a match surrounded by more digits or dots is discarded, so the 1.2.3.4
inside 1.2.3.4.5 is not reported as an address.
How to extract IP addresses from text
- Paste your text. Server logs, firewall rules, config files, email headers, a spreadsheet column — anything with addresses in it.
- Choose what to include. IPv6 is on by default. Tick Public addresses only to hide the internal ranges, which is usually what you want when reviewing traffic.
- Click Extract. Candidates are matched, then validated: every octet must be 0–255, leading zeros are rejected, and anything embedded in a longer dotted run is discarded.
- Copy or download. Copy the plain list, or download a .csv carrying the address, IP version and type.
What comes out
- IPv4 addresses, with CIDR suffixes preserved when present, so
10.0.0.0/8stays intact. - IPv6 addresses, including compressed
::forms. - A type label for each: public, private, loopback, link-local, carrier NAT, multicast or reserved.
- Numeric sorting —
10.0.0.9before10.0.0.10, which alphabetical sorting gets backwards. - Counts per type, so you can see at a glance how much of a log is internal traffic.
- CSV export carrying address, version and type.
Which ranges are recognised
Private ranges follow RFC 1918: 10.0.0.0/8, 172.16.0.0/12 and
192.168.0.0/16. Also identified are loopback (127.0.0.0/8), link-local
(169.254.0.0/16), carrier-grade NAT (100.64.0.0/10), multicast
(224.0.0.0/4) and reserved space.
For IPv6: ::1 is loopback, fe80::/10 is link-local, fc00::/7 is
unique local — the IPv6 equivalent of a private range — and ff00::/8 is multicast. Anything
else is reported as public. There is no limit on how much text you can paste.
Why the log never leaves your device
Matching runs as JavaScript in your browser. Nothing you paste is transmitted.
Server logs are among the worst things to paste into an online tool. A single access log line can carry a session token in a query string, a customer's IP address, an internal hostname and a file path that reveals your directory structure. IP addresses are personal data under GDPR in their own right. Extracting locally means none of that is disclosed to anyone.
What it does not do
This tool finds and classifies addresses. It deliberately does not:
- Look anything up. No geolocation, no reverse DNS, no WHOIS — all of those would mean sending your addresses to a third party, which is the opposite of the point.
- Expand CIDR ranges.
10.0.0.0/24is reported as written, not as 256 addresses. - Match every exotic IPv6 form. Full and compressed notation are handled;
IPv4-mapped forms such as
::ffff:192.0.2.1may be reported as the IPv4 part. - Count occurrences. With duplicates removed you get the unique set, not a frequency ranking.
Who extracts IP addresses
- System administrators — pulling the unique client addresses out of an access log to spot patterns.
- Security work — collecting addresses from an incident log to review or block.
- Network documentation — extracting every address referenced in a set of config files.
- Support — finding the addresses in an email header while tracing a delivery problem.
- Migration — listing hard-coded addresses in a codebase before changing hosting.
Compared with writing the pattern yourself
A regex for IP addresses is a classic interview question and a classic source of quiet bugs — the range check is what most attempts get wrong, and the result is a list polluted with version numbers. This tool bakes those rules in.
If you need a different pattern entirely, the regex extractor lets you write your own and runs it safely. For the email addresses and URLs in the same log, use the email and URL extractor. If your log is inside a document rather than plain text, extract the text first with the PDF text extractor.
IP address format standards and parsing edge cases
IPv4 is defined in RFC 791: four decimal octets in the range 0–255 separated by
dots. IPv6 is defined in RFC 8200: eight groups of four hexadecimal digits separated by
colons, with :: as shorthand for one or more consecutive groups of zeros.
Both formats are matched.
Four edge cases: (a) loopback addresses 127.0.0.1 and ::1 are returned like any other
address — filtering private or reserved ranges requires post-processing; (b) link-local
IPv6 addresses include a percent-sign scope ID per RFC 4007 (e.g., fe80::1%eth0)
— the extractor returns the address without the scope ID; (c) IPv4-mapped IPv6 addresses
such as ::ffff:192.0.2.1 are returned as IPv6; (d) IPv4 octets with leading
zeros (e.g., 010.000.000.001) are not matched — they are ambiguous (octal in
some C contexts, invalid in dotted-decimal notation) and suppressing them avoids false
positives from numeric fields.
Frequently asked questions
How do I extract all IP addresses from a log file?
Paste the log above and click Extract. Every valid address is listed, deduplicated and sorted numerically, with a type label.
Does it filter out version numbers?
Yes. Octets must be 0–255, leading zeros are rejected, and matches embedded in longer dotted runs are discarded — which removes most version strings.
Is my log uploaded to a server?
No. Everything runs in your browser. That matters here, because logs routinely contain tokens, internal hostnames and personal data alongside the addresses.
What is the difference between public and private addresses?
Private ranges (10.x, 172.16–31.x, 192.168.x) are used inside networks and are not routable on the internet. Tick Public addresses only to see just the external ones.
Does it show where an address is located?
No, deliberately. Geolocation would mean sending your addresses to a third-party service, which would undo the reason for extracting them locally.
Does it handle IPv6?
Yes, including compressed :: notation. Switch it off if a document's hex identifiers are producing false matches.
Are CIDR ranges supported?
They are preserved as written — 10.0.0.0/8 stays as one entry. The range is not expanded into individual addresses.
Why is 192.168.01.1 not matched?
A leading zero in an octet is not valid in an IP address. It is almost always a version number, so it is rejected on purpose.