> For the complete documentation index, see [llms.txt](https://docs.onum.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.onum.com/pipelines/actions/transformation/field-transformation/field-transformation-operations/extraction/extract-mac-addresses.md).

# Extract MAC Addresses

## Description

This operation extracts MAC addresses from a given input text. It supports various formats, including colon and hyphen separators.

***

## Data types

These are the input/output expected data types for this operation:

### Input data

`String` - Input events to extract MAC addresses from.

### Output data

`ListString` - List of comma-separated extracted MAC addresses.

***

## Parameters

These are the parameters you need to configure to use this operation (mandatory parameters are marked with a <mark style="color:red;">**\***</mark>):

<details>

<summary>Output Separator</summary>

Select the separator in the input MAC addresses. Choose between **Colon (:)** (default), **Hyphen (-)** and **None**.

</details>

<details>

<summary>Sort Results</summary>

Set this parameter to **true** if you want to sort the extracted MAC adresses alphabetically, or **false** if you want to display them as they appear in the original input data. The default value is **false**.

</details>

<details>

<summary>Unique Only</summary>

Set this parameter to **true** (default value) if you want to include only unique MAC addresses in your results.&#x20;

</details>

***

## Example

Suppose you want to **extract** all the **MAC addresses** from a given series of events. To do it:

1. In your Pipeline, open the required [Action](/pipelines/actions.md) configuration and select the input **Field**.
2. In the **Operation** field, choose **Extract MAC Addresses**.
3. Set **Output Separator** to **Colon (:)**.
4. Set **Sort Results** to **false**.
5. Set **Unique Only** to **true**.
6. Give your **Output field** a name and click **Save**.

For example, given this input text:

```
We need to prioritize the replacement of the aging routers on the executive floor," Samantha noted in her report. "The Cisco device at 4F:5E:AB:23:CD:01 has been experiencing memory leaks, and the backup unit with MAC address 84:7B:EB:22:10:DF isn't configured properly for automatic failover.
```

You'll get the following:

```
4F:5E:AB:23:CD:01,84:7B:EB:22:10:DF
```

{% hint style="info" %}
You can try out operations with specific values using the **Input** field above the operation. You can enter the value in the example above and check the result in the **Output** field.
{% endhint %}
