I need to create an alert for when my DHCP server is not returning acknowledgement. Please help
but I am specifically looking to create an alert for DHCP broadcasts with no acknowledgement//
Hi @waJesu i am not much sure of this.. but, let me ask, how to find out "DHCP broadcasts with no acknowledgement".. is it updated into some logs or you have some splunk search query?
Are you logging data from your DHCP server in Splunk? If so, see https://www.duanewaddle.com/proving-a-negative/. If not, then start onboarding DHCP info then read the information at the link above.
Yeah the DHCP is bring logs into Splunk but I am specifically looking to create an alert for DHCP broadcasts with no acknowledgement. Please help along those lines. Thank you for the link. Though it doesn't have my solution, it is still helpful information to keep.