Alerting

Alert for DHCP Broadcasts without acknowledgement

waJesu
Path Finder

I need help coming up with an alert for DHCP broadcasts with no acknowledgement.  The DHCP is injesting logs into Splunk.

Labels (1)

inventsekar
SplunkTrust
SplunkTrust

Hi @waJesu .. please provide us some more details.. do you use any splunkbase apps/addons, etc

or how do you configured DHCP to splunk integration.. are you referring to Splunk indexer to UF indexer acknowledgement feature or its related to DHCP?..

0 Karma

waJesu
Path Finder

You know how a DHCP returns a DHCPACK after the other 3 steps (DHCPDISCOVER, DHCPOFFER, and DHCPREQUEST). From the logs, I want to identify events where a DHCP broadcast has no DHCPACK. I hope I have clarified my need. So far I have used: index=* host=<dhcp servername> "no free leases". I believe there is a better query and maybe narrow results by hostname.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...