I need help coming up with an alert for DHCP broadcasts with no acknowledgement. The DHCP is injesting logs into Splunk.
Hi @waJesu .. please provide us some more details.. do you use any splunkbase apps/addons, etc
or how do you configured DHCP to splunk integration.. are you referring to Splunk indexer to UF indexer acknowledgement feature or its related to DHCP?..
You know how a DHCP returns a DHCPACK after the other 3 steps (DHCPDISCOVER, DHCPOFFER, and DHCPREQUEST). From the logs, I want to identify events where a DHCP broadcast has no DHCPACK. I hope I have clarified my need. So far I have used: index=* host=<dhcp servername> "no free leases". I believe there is a better query and maybe narrow results by hostname.