Getting Data In

How to get DHCP scope information in DHCP logs into Splunk?

kiran331
Builder

Hi

How can I get the DHCP scope information in DHCP logs, or is there way to get that information into Splunk and correlate?

Tags (2)

christian_clout
Explorer

Hi,

I had the same question and ended up creating and using a custom TA for our Windows 2008 R2 based DHCP servers.

It's rather simple. It's a scripted input which runs on those DHCP host via their universal forwarder and performs:

netsh dhcp server show mibinfo

This shows all scopes, number of addresses in use/free and pending offers for the DHCP server which I then index in Splunk.

0 Karma

kiran331
Builder

Thanks for response! I tried this one, It is not showing the Scope names, Do you know how to get the scope names? It showing sub nets and use/free..

0 Karma

christian_clout
Explorer

Hi Kiran331,

The information is little all over the place, at least in my case. 🙂

I get mine from Active Directory and then correlate them together.

So for example, from the output of netsh dhcp server show mibinfo:

Subnet = 10.11.12.0.
        No. of Addresses in use = 0.
        No. of free Addresses = 1.
        No. of pending offers = 0.

And the following from my Active Directory entries for subnets (Base DN="CN=Subnets,CN=Sites,CN=Configuration,DC=your,DC=company,DC=com", Filter="(&(objectClass=subnet))"):

siteObject,name,description
"MY_SITE_CODE","10.11.12.0/24","My Company Site ABC Scope"

Note: You can use SA-LDAPSearch to query your Active Directory or a custom script (I use perl).

Then you should be able to get the scope IP range, the site (or whatever) it belongs to and a nice description for it.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...