DHCP Server Logs Integration
Overview
DHCP server logs provide IP address assignment history and device identification data. KYRA MDR collects DHCP logs for asset discovery, rogue device detection, and network forensics. Supports ISC DHCP, Microsoft DHCP, and Kea DHCP.
Prerequisites
- A KYRA MDR Collector installed and running
- DHCP server with logging enabled
- Network connectivity from the DHCP server to the collector
- Administrative access to the DHCP server
Configuration
Configure DHCP logging:
For ISC DHCP (dhcpd):
log-facility local6;Forward via rsyslog:
local6.* @@<collector-ip>:514For Kea DHCP:
{ "Logging": { "loggers": [{ "name": "kea-dhcp4", "output_options": [{"output": "syslog:local6"}], "severity": "INFO" }] }}Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| DHCPDISCOVER | Client discovery broadcast | New device detection |
| DHCPOFFER | Server address offer | Address pool monitoring |
| DHCPREQUEST | Client address request | Device tracking |
| DHCPACK | Address assignment confirmation | IP-to-MAC mapping |
| DHCPRELEASE | Address release events | Device departure tracking |
| DHCPNAK | Negative acknowledgment | Configuration issues |
Troubleshooting
No DHCP logs: Verify the log facility is correctly configured and syslog forwarding is enabled.
Missing MAC addresses: Ensure the DHCP server logs include client hardware addresses.
Windows DHCP: Microsoft DHCP writes audit logs to files by default. Use a log shipper to forward them.
Contact kyra@seekerslab.com for support.