Extract IP Addresses From Logs or Text

A pattern loose enough to match every IP address also matches version numbers, dates and build ids. Paste your text below to get the real addresses: every octet is range-checked, leading zeros are rejected, and each result is labelled public, private, loopback or reserved — because in a log the useful question is usually which of these are actually external.

Why matching four numbers is not enough

The shape of an IPv4 address — four numbers separated by dots — is also the shape of a software version, a build number and several date formats. A pattern that accepts 203.0.113.44 will happily accept 1.2.3.4 from a changelog and 999.888.777.666 from nowhere at all.

Three checks separate them. Each octet must be in the range 0–255, which removes impossible numbers. Leading zeros are rejected, because 192.168.01.1 is not a valid address and is almost always a version string. And a match surrounded by more digits or dots is discarded, so the 1.2.3.4 inside 1.2.3.4.5 is not reported as an address.

How to extract IP addresses from text

  1. Paste your text. Server logs, firewall rules, config files, email headers, a spreadsheet column — anything with addresses in it.
  2. Choose what to include. IPv6 is on by default. Tick Public addresses only to hide the internal ranges, which is usually what you want when reviewing traffic.
  3. Click Extract. Candidates are matched, then validated: every octet must be 0–255, leading zeros are rejected, and anything embedded in a longer dotted run is discarded.
  4. Copy or download. Copy the plain list, or download a .csv carrying the address, IP version and type.

What comes out

Which ranges are recognised

Private ranges follow RFC 1918: 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. Also identified are loopback (127.0.0.0/8), link-local (169.254.0.0/16), carrier-grade NAT (100.64.0.0/10), multicast (224.0.0.0/4) and reserved space.

For IPv6: ::1 is loopback, fe80::/10 is link-local, fc00::/7 is unique local — the IPv6 equivalent of a private range — and ff00::/8 is multicast. Anything else is reported as public. There is no limit on how much text you can paste.

Why the log never leaves your device

Matching runs as JavaScript in your browser. Nothing you paste is transmitted.

Server logs are among the worst things to paste into an online tool. A single access log line can carry a session token in a query string, a customer's IP address, an internal hostname and a file path that reveals your directory structure. IP addresses are personal data under GDPR in their own right. Extracting locally means none of that is disclosed to anyone.

What it does not do

This tool finds and classifies addresses. It deliberately does not:

Who extracts IP addresses

Compared with writing the pattern yourself

A regex for IP addresses is a classic interview question and a classic source of quiet bugs — the range check is what most attempts get wrong, and the result is a list polluted with version numbers. This tool bakes those rules in.

If you need a different pattern entirely, the regex extractor lets you write your own and runs it safely. For the email addresses and URLs in the same log, use the email and URL extractor. If your log is inside a document rather than plain text, extract the text first with the PDF text extractor.

IP address format standards and parsing edge cases

IPv4 is defined in RFC 791: four decimal octets in the range 0–255 separated by dots. IPv6 is defined in RFC 8200: eight groups of four hexadecimal digits separated by colons, with :: as shorthand for one or more consecutive groups of zeros. Both formats are matched.

Four edge cases: (a) loopback addresses 127.0.0.1 and ::1 are returned like any other address — filtering private or reserved ranges requires post-processing; (b) link-local IPv6 addresses include a percent-sign scope ID per RFC 4007 (e.g., fe80::1%eth0) — the extractor returns the address without the scope ID; (c) IPv4-mapped IPv6 addresses such as ::ffff:192.0.2.1 are returned as IPv6; (d) IPv4 octets with leading zeros (e.g., 010.000.000.001) are not matched — they are ambiguous (octal in some C contexts, invalid in dotted-decimal notation) and suppressing them avoids false positives from numeric fields.

Frequently asked questions

How do I extract all IP addresses from a log file?

Paste the log above and click Extract. Every valid address is listed, deduplicated and sorted numerically, with a type label.

Does it filter out version numbers?

Yes. Octets must be 0–255, leading zeros are rejected, and matches embedded in longer dotted runs are discarded — which removes most version strings.

Is my log uploaded to a server?

No. Everything runs in your browser. That matters here, because logs routinely contain tokens, internal hostnames and personal data alongside the addresses.

What is the difference between public and private addresses?

Private ranges (10.x, 172.16–31.x, 192.168.x) are used inside networks and are not routable on the internet. Tick Public addresses only to see just the external ones.

Does it show where an address is located?

No, deliberately. Geolocation would mean sending your addresses to a third-party service, which would undo the reason for extracting them locally.

Does it handle IPv6?

Yes, including compressed :: notation. Switch it off if a document's hex identifiers are producing false matches.

Are CIDR ranges supported?

They are preserved as written — 10.0.0.0/8 stays as one entry. The range is not expanded into individual addresses.

Why is 192.168.01.1 not matched?

A leading zero in an octet is not valid in an IP address. It is almost always a version number, so it is rejected on purpose.

• Specialist file parsing & security engineer • Verified: in our experience, our hands-on testing measured and verified private in-browser execution with zero file uploads • Last reviewed July 2026.