IP Port Extractor
Extract and normalize IP endpoints in original log order
Up to 1 MiB / 1,000 matches. Accepts strict IPv4:port, bracketed IPv6:port and optional localhost. Ports are 0β65535; 0 is a reserved value, not a usable remote service. No DNS, scanning, zones or hostname extraction.
Run the tool or try an example to see results.
The full guide also includes pitfalls, worked examples, snippets, FAQs, and related tools for checking results or troubleshooting.
About this tool
Turn pasted logs into a reviewable endpoint list. The parser accepts strict dotted-decimal IPv4:port and bracketed [IPv6]:port, including an IPv4 tail inside IPv6. Optional localhost matching is explicit. Address syntax is validated before a match is accepted; a fragment of an invalid IPv4 or malformed IPv6 is not treated as a valid suffix. Ports contain at most five decimal digits and must be 0β65535. The output normalizes IPv6 compression, letter case and port leading zeros. With deduplication enabled, equivalent normalized endpoints appear once, at their first position in the source. Without sorting, mixed IPv4 and IPv6 retain source order; sorting uses deterministic text order, not numeric address order. Each detail row includes the original match and its zero-based UTF-16 offset. Input is limited to 1 MiB and 1,000 accepted matches. This is a conservative text extractor, not a full log grammar, DNS resolver or connectivity scan; unbracketed IPv6 endpoints, zones and ordinary hostnames are outside its scope. No raw log draft is saved.
Failure Clinic (Common Pitfalls)
A list extracted from text is not a connectivity result
Cause: No connection, DNS resolution, route check or firewall evaluation takes place. Skipped malformed tokens are not proof that the rest of the log contains no endpoints.
Fix: First compare the list with the original log format. Use an authorized network diagnostic separately when actual reachability matters.
Scenario Recipes
Reconcile retry endpoints in a mixed log
Goal: Compare normalized endpoint identity without losing the original order.
- Paste a short log sample containing both IPv4:port and [IPv6]:port.
- Run with deduplication enabled; inspect the original matches and offsets when several spellings collapse.
- Disable deduplication to inspect repeated occurrences, or enable text sorting for a stable comparison list.
Result: Only supported endpoint tokens, normalized and linked back to their original text.
Production Snippets
Equivalent IPv6 endpoints versus malformed input
text
[2001:0DB8::1]:0443
192.0.2.1:80
[2001:db8:0:0:0:0:0:1]:443
[2001:::1]:80
Deduplicated output:
[2001:db8::1]:443
192.0.2.1:80Frequently Asked Questions
Why are equivalent IPv6 spellings merged?
Deduplication compares normalized address-and-port pairs. [2001:0db8::1]:0443 and [2001:db8:0:0:0:0:0:1]:443 become [2001:db8::1]:443. Disable deduplication when repeated occurrences matter.
Does port 0 represent a reachable service?
No. Zero fits the numeric port field but is reserved. A parsed endpoint is not evidence of a listening service, an open firewall rule or successful routing.
Why was an endpoint-like token skipped?
Invalid octets, malformed compression, zones, ordinary hostnames, excessive port digits and adjoining token characters are not accepted. Encoded or nonstandard log formats may need a dedicated parser; compare the source details before relying on a complete inventory.
Can I use this as an IP-only extractor?
No. This tool requires an explicit port. IPv6 needs brackets so the final colon is not confused with part of the address. Localhost is the only optional named host.
Keep browsing