<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best way to get Windows DHCP logs to Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Best-way-to-get-Windows-DHCP-logs-to-Splunk/m-p/570415#M101092</link>
    <description>&lt;P&gt;The only problem with this way is DHCP log file size on DC.&lt;/P&gt;&lt;P&gt;I am also trying with Splunk Stream app, but it is complicated to fulfil the use case,&lt;/P&gt;&lt;P&gt;MAC - IP - Hostname&amp;nbsp;&lt;/P&gt;&lt;P&gt;Details from the logs, with stream we get all the data from DORA process and I believe DHCPREQUEST and DHCPACK is where I should get the details.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But not able to figure out the fields, m&lt;SPAN&gt;ostly I should received the desired values on this fields but not always this is true.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;chaddr&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;yiaddr&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;client_fqdn&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Has anyone successfully configured stream for DHCP logs and have getting the logs required for asset inventory (MAC-IP-Hostname)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Oct 2021 06:30:15 GMT</pubDate>
    <dc:creator>PratikPashte</dc:creator>
    <dc:date>2021-10-11T06:30:15Z</dc:date>
    <item>
      <title>Best way to get Windows DHCP logs to Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Best-way-to-get-Windows-DHCP-logs-to-Splunk/m-p/568034#M100831</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am trying to get Windows DHCP logs to Splunk and trying to use below way to get the same, but wanted to look if there is any better way to ingest the DHCP logs to Splunk.&lt;/P&gt;&lt;P&gt;Using Deployment server to get the logs with inputs.conf file,&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;[monitor://C:\Windows\System32\dhcp]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;sourcetype&lt;/SPAN&gt; &lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; dhcp&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;crcSalt&lt;/SPAN&gt; &lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; &amp;lt;SOURCE&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;alwaysOpenFile&lt;/SPAN&gt; &lt;SPAN&gt;=&lt;/SPAN&gt; &lt;SPAN&gt;1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;disabled&lt;/SPAN&gt; &lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; false&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;index&lt;/SPAN&gt; &lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; dhcplogs&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;whitelist&lt;/SPAN&gt; &lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; Dhcp.+\.log&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;And then to install below app at search heads to parse the logs,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;A href="https://splunkbase.splunk.com/app/4359/#/details" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/4359/#/details&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;I haven't completed the setup prior to that was getting some advise if this the best way to go ahead or any other way we have to ingest it better.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;If this the best way is there anything i need to be aware prior to the setup, Thanks in advanced.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Regards,&lt;/DIV&gt;&lt;DIV&gt;Pratik Pashte&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 13:09:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Best-way-to-get-Windows-DHCP-logs-to-Splunk/m-p/568034#M100831</guid>
      <dc:creator>PratikPashte</dc:creator>
      <dc:date>2021-09-22T13:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: Best way to get Windows DHCP logs to Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Best-way-to-get-Windows-DHCP-logs-to-Splunk/m-p/568090#M100837</link>
      <description>&lt;P&gt;Install the Splunk UF on the hosts and also push this add-on to all the UF's and install it on your SH as well which makes your job easy in field extractions.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 16:18:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Best-way-to-get-Windows-DHCP-logs-to-Splunk/m-p/568090#M100837</guid>
      <dc:creator>Roy_9</dc:creator>
      <dc:date>2021-09-22T16:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: Best way to get Windows DHCP logs to Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Best-way-to-get-Windows-DHCP-logs-to-Splunk/m-p/568192#M100846</link>
      <description>&lt;P&gt;Which means I am on the right track, Thanks Roy.&lt;/P&gt;&lt;P&gt;But would also like to understand is there any other way as well to pull the DHCP logs to Splunk?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 05:29:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Best-way-to-get-Windows-DHCP-logs-to-Splunk/m-p/568192#M100846</guid>
      <dc:creator>PratikPashte</dc:creator>
      <dc:date>2021-09-23T05:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: Best way to get Windows DHCP logs to Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Best-way-to-get-Windows-DHCP-logs-to-Splunk/m-p/568193#M100847</link>
      <description>I think that this is the easiest and best way to do it with splunk. Other ways are more complicated than this.</description>
      <pubDate>Thu, 23 Sep 2021 05:55:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Best-way-to-get-Windows-DHCP-logs-to-Splunk/m-p/568193#M100847</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-09-23T05:55:35Z</dc:date>
    </item>
    <item>
      <title>Re: Best way to get Windows DHCP logs to Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Best-way-to-get-Windows-DHCP-logs-to-Splunk/m-p/570415#M101092</link>
      <description>&lt;P&gt;The only problem with this way is DHCP log file size on DC.&lt;/P&gt;&lt;P&gt;I am also trying with Splunk Stream app, but it is complicated to fulfil the use case,&lt;/P&gt;&lt;P&gt;MAC - IP - Hostname&amp;nbsp;&lt;/P&gt;&lt;P&gt;Details from the logs, with stream we get all the data from DORA process and I believe DHCPREQUEST and DHCPACK is where I should get the details.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But not able to figure out the fields, m&lt;SPAN&gt;ostly I should received the desired values on this fields but not always this is true.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;chaddr&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;yiaddr&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;client_fqdn&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Has anyone successfully configured stream for DHCP logs and have getting the logs required for asset inventory (MAC-IP-Hostname)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Oct 2021 06:30:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Best-way-to-get-Windows-DHCP-logs-to-Splunk/m-p/570415#M101092</guid>
      <dc:creator>PratikPashte</dc:creator>
      <dc:date>2021-10-11T06:30:15Z</dc:date>
    </item>
  </channel>
</rss>

