本文にスキップ

DHCP Server Logs Integration

Overview

DHCP server logs provide IP address assignment history and device identification data. KYRA MDR collects DHCP logs for asset discovery, rogue device detection, and network forensics. Supports ISC DHCP, Microsoft DHCP, and Kea DHCP.

Prerequisites

  • A KYRA MDR Collector installed and running
  • DHCP server with logging enabled
  • Network connectivity from the DHCP server to the collector
  • Administrative access to the DHCP server

Configuration

Configure DHCP logging:

For ISC DHCP (dhcpd):

/etc/dhcp/dhcpd.conf
log-facility local6;

Forward via rsyslog:

/etc/rsyslog.d/dhcp.conf
local6.* @@<collector-ip>:514

For Kea DHCP:

{
"Logging": {
"loggers": [{
"name": "kea-dhcp4",
"output_options": [{"output": "syslog:local6"}],
"severity": "INFO"
}]
}
}

Collected Log Types

Log TypeDescriptionSecurity Use
DHCPDISCOVERClient discovery broadcastNew device detection
DHCPOFFERServer address offerAddress pool monitoring
DHCPREQUESTClient address requestDevice tracking
DHCPACKAddress assignment confirmationIP-to-MAC mapping
DHCPRELEASEAddress release eventsDevice departure tracking
DHCPNAKNegative acknowledgmentConfiguration issues

Troubleshooting

No DHCP logs: Verify the log facility is correctly configured and syslog forwarding is enabled.

Missing MAC addresses: Ensure the DHCP server logs include client hardware addresses.

Windows DHCP: Microsoft DHCP writes audit logs to files by default. Use a log shipper to forward them.

Contact kyra@seekerslab.com for support.