You can configure collecting Windows DHCP logs using a Standard Collector or content pack integration (onboarded prior to July 26, 2026):
| Collection Method | Description |
| --------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Standard Collector (basic) overview | Forward logs to Cortex XDR from Windows DHCP logs using Elasticsearch Filebeat with the Windows DHCP data source. |
| Link to Standard Collector instructions | [Ingest logs from Windows DHCP using Elasticsearch Filebeat](windows-dhcp-via-elasticsearch-filebeat/ingest-logs-from-windows-dhcp-using-elasticsearch-filebeat) |
| Link to content pack details (onboarded prior to July 26, 2026) | The [Microsoft DHCP](https://cortex.marketplace.pan.dev/marketplace/details/MicrosoftDHCP) content pack processes and normalizes audit logs from the Dynamic Host Configuration Protocol (DHCP) service for security analysis in Cortex XSIAM. It includes modeling Rules and parsing rules for events collected using the XDR Collector via the **`microsoft_dhcp_raw dataset`**. |