Getting Data In

Best way to get Windows DHCP logs to Splunk

PratikPashte
Explorer

Hello,

I am trying to get Windows DHCP logs to Splunk and trying to use below way to get the same, but wanted to look if there is any better way to ingest the DHCP logs to Splunk.

Using Deployment server to get the logs with inputs.conf file,

[monitor://C:\Windows\System32\dhcp]
sourcetype = dhcp
crcSalt = <SOURCE>
alwaysOpenFile = 1
disabled = false
index = dhcplogs
whitelist = Dhcp.+\.log
 
And then to install below app at search heads to parse the logs,
 
 
I haven't completed the setup prior to that was getting some advise if this the best way to go ahead or any other way we have to ingest it better.
 
If this the best way is there anything i need to be aware prior to the setup, Thanks in advanced.
 
 
Regards,
Pratik Pashte
 
 

 

Labels (3)
0 Karma

PratikPashte
Explorer

The only problem with this way is DHCP log file size on DC.

I am also trying with Splunk Stream app, but it is complicated to fulfil the use case,

MAC - IP - Hostname 

Details from the logs, with stream we get all the data from DORA process and I believe DHCPREQUEST and DHCPACK is where I should get the details.

 

But not able to figure out the fields, mostly I should received the desired values on this fields but not always this is true.

chaddr
yiaddr
client_fqdn

Has anyone successfully configured stream for DHCP logs and have getting the logs required for asset inventory (MAC-IP-Hostname)?

 

0 Karma

Roy_9
Motivator

Install the Splunk UF on the hosts and also push this add-on to all the UF's and install it on your SH as well which makes your job easy in field extractions.

0 Karma

PratikPashte
Explorer

Which means I am on the right track, Thanks Roy.

But would also like to understand is there any other way as well to pull the DHCP logs to Splunk?

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
I think that this is the easiest and best way to do it with splunk. Other ways are more complicated than this.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...