Alerting

Alert for DHCP Broadcasts without acknowledgement

waJesu
Path Finder

I need help coming up with an alert for DHCP broadcasts with no acknowledgement.  The DHCP is injesting logs into Splunk.

Labels (1)

inventsekar
SplunkTrust
SplunkTrust

Hi @waJesu .. please provide us some more details.. do you use any splunkbase apps/addons, etc

or how do you configured DHCP to splunk integration.. are you referring to Splunk indexer to UF indexer acknowledgement feature or its related to DHCP?..

0 Karma

waJesu
Path Finder

You know how a DHCP returns a DHCPACK after the other 3 steps (DHCPDISCOVER, DHCPOFFER, and DHCPREQUEST). From the logs, I want to identify events where a DHCP broadcast has no DHCPACK. I hope I have clarified my need. So far I have used: index=* host=<dhcp servername> "no free leases". I believe there is a better query and maybe narrow results by hostname.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...