DHCP Integration
The ability to correlate the origin of an event detected by the Sensor with the IP address a host was using at the same time is the primary reason to collect DHCP logs. This document describes the process for forwarding DHCP logs to the VMware NSX Network Detection and Response for ingestion and processing.
About DHCP
The Dynamic Host Configuration Protocol (DHCP) is a UDP protocol that dynamically allocates IP addresses from a pool and reclaims them when they are no longer in use. Systems running Windows Server provide DHCP services in many environments.
Typically, you can forward system logs using Windows Event Forwarding (WEF), however WEF does not support DHCP logs. Therefore you must deploy a third-party solution to collect and forward DHCP logs from Windows Servers. There are a number of solutions available: this document describes using NXLog.
Requirements
The following are required for integration:
-
At least one Sensor deployed in either a Hosted or On-Premises environment.
-
Configure the Windows Server 2016, 2012, or 2008 providing DHCP services to save DHCP logs.
-
Download, install, and configure the NXLog Community Edition.
Note:There are other third-party solutions available to collect and forward DHCP logs from Windows Servers. You do not have to use NXLog.
-
Configure the User Portal to ingest the DHCP data.
Configure the DHCP Server
Install and Configure NXLog
Windows Event Forwarding does not support DHCP logs. To collect and forward DHCP logs from Windows Servers you must install a third-party solution. This document provides an overview of configuring NXLog.
Refer to the NXLog documentation for complete details.
Configure the Sensor
Once the Windows Server has been set up properly, the Sensor can be configured to ingest the DHCP logs.
Saving the collector triggers a reconfiguration on the sensor, after which a DHCP ingestion process is ready to receive DHCP logs on the specified port number. The progress of the reconfiguration action can be followed on the Admin→Appliances→Monitoring logs tab.