Extract MAC Addresses From Logs or Text

A MAC address is six hex bytes, but it is written three different ways — 00:1A:2B:3C:4D:5E, 00-1A-2B-3C-4D-5E and Cisco’s 001a.2b3c.4d5e — and a pattern loose enough to catch all three also catches unrelated hex. Paste your text below to get the real addresses, normalised to one format, deduplicated, and each one labelled unicast or multicast and universal or locally set.

What a MAC address is

A MAC address is the hardware address of a network interface: six bytes, or 48 bits, usually shown as twelve hex digits. It identifies a device on a local network, where an IP address identifies it on the internet. Every network card, Wi-Fi radio and virtual adapter has one.

The same six bytes are written in three notations. Windows and many tools use hyphens (00-1A-2B-3C-4D-5E); Unix, Linux and most documentation use colons (00:1a:2b:3c:4d:5e); Cisco equipment groups the bytes in threes separated by dots (001a.2b3c.4d5e). All three describe the identical address, which is why a viewer that normalises them to one form is useful when a log mixes sources.

The first three bytes are the OUI, an identifier assigned to the hardware vendor; the last three are assigned by that vendor to the individual device.

How to extract MAC addresses from text

  1. Paste your text. ARP tables, DHCP leases, switch and router output, packet-capture summaries, syslog — anything with hardware addresses in it.
  2. Choose the output format. Pick colon, hyphen, Cisco dotted or bare. Every address found is rewritten to that single format, so a file mixing all three styles comes out consistent.
  3. Click Extract. The three notations are matched, then anything sitting inside a longer hex string is discarded, so a MAC is not cut out of the middle of a token.
  4. Copy or download. Copy the plain list, or download a .csv carrying the address, its cast, its administration and the OUI (the first three bytes, which identify the vendor).

What comes out

What is supported, and what is not

Matched: the colon form, the hyphen form and the Cisco dotted-quad form, in upper or lower case. Every match is validated as exactly six bytes and then boundary-checked: an address touching another hex digit or separator on either side is rejected, so a MAC is never sliced out of the middle of a longer hex token such as a hash or a serial number.

Not done: vendor lookup. The OUI is shown, but it is not resolved to a company name. Resolving it means either shipping a large database or, far worse, sending your addresses to an online OUI service — which would defeat the point of extracting them privately. Look the OUI up yourself against the IEEE registry if you need the vendor.

Not matched: EUI-64 (64-bit) addresses, and the MAC portion embedded inside an IPv6 link-local address, which needs un-flipping first. Bare twelve-digit hex with no separators is not matched either, because at that point it is indistinguishable from any other 48-bit hex value.

Why the log never leaves your device

Matching runs as JavaScript in your browser. Nothing you paste is transmitted. For the full explanation of how browser-based processing works, see the security page.

Network logs are sensitive in their own right. A MAC address is a stable device identifier — it can track a specific laptop or phone across a network — and it usually appears next to IP addresses, hostnames and usernames in the same log line. Extracting locally means none of that surrounding context is disclosed to anyone.

What this tool does not do

This tool finds, normalises and classifies addresses. It deliberately does not:

Who extracts MAC addresses

MAC addresses compared with IP addresses and other identifiers

A MAC address identifies a device on the local network and normally never changes; an IP address identifies it on the internet and is often reassigned. They appear side by side in ARP tables, DHCP leases and firewall logs, which is why the two extractors pair up. To pull the IP addresses out of the same log, use the IP address extractor.

For the hashes and UUIDs that show up in the same operational data, use the hash extractor and the UUID extractor. For any other pattern, the regex extractor lets you write your own and runs it safely in your browser.

Frequently asked questions

How do I extract all MAC addresses from a log?

Paste the log above and click Extract. Every address in colon, hyphen or Cisco form is listed, rewritten to one format, deduplicated and classified.

Does it handle Cisco dotted MAC addresses?

Yes. The Cisco form 001a.2b3c.4d5e is matched alongside the colon and hyphen forms, and all three are normalised to whichever output format you choose.

Can it tell me the vendor of a MAC address?

It shows the OUI — the first three bytes, which identify the vendor — but it does not resolve that to a company name. Doing so would need a database or a request to a third-party service, which would send your addresses off your device.

What does 'locally administered' mean?

The second bit of the first byte is set, meaning the address was assigned by software rather than burned into hardware. Randomised phone Wi-Fi, virtual machines and hand-set addresses all show up this way.

Is my log uploaded to a server?

No. Matching runs entirely in your browser. Nothing you paste is transmitted, which matters because MAC addresses are stable device identifiers usually logged next to IPs and usernames.

Why is a 12-character hex string not matched?

Bare hex with no colons, hyphens or dots is indistinguishable from any other 48-bit value, so it is not treated as a MAC on purpose. Add separators if it really is an address.

What is the difference between unicast and multicast here?

The lowest bit of the first byte. Unicast addresses one device; multicast addresses a group. The tool labels each and can filter to unicast only.

• Specialist file parsing & security engineer • Verified: in our experience, our hands-on testing measured and verified private in-browser execution with zero file uploads • Last reviewed August 2026.