Microsoft DHCP (v1.0.10)

Dynamic Host Configuration Protocol (DHCP) is a client/server protocol that automatically provides an Internet Protocol (IP) host with its IP address and other related configuration information such as the subnet mask and default gateway.

Author
Cortex XSOAR
Support
xsoar
URL
https://www.paloaltonetworks.com/cortex
Categories
IT Services

Modeling rules (1)

Parsing rules (1)

README

Microsoft DHCP

This pack includes Cortex XSIAM content.

Configuration on Server Side

  1. Start the DHCP administration tool (go to Start → Programs → Administrative Tools, and click DHCP).
  2. Right-click the DHCP server, and select Properties from the context menu.
  3. Select the General tab.
  4. Select the Enable DHCP audit logging checkbox.
  5. Click OK.

Note:
Time parsing is supported only when the below fields have the mentioned formats:

Collect Events from Vendor

In order to use the collector, use the XDRC (XDR Collector) option.

XDRC (XDR Collector)

To create or configure the Filebeat collector, use the information described here and here.

You can configure the vendor and product by replacing [vendor]_[product]_raw with microsoft_dhcp_raw.

As cortex XSIAM provides YAML template for DHCP, you can use the following steps to create a collection profile:

  1. In XSIAM, select SettingsConfigurationsXDR CollectorsProfiles+Add ProfileWindows.
  2. Select Filebeat profile or Winlogbeat profile, then click Next.
  3. Configure the General Information parameters: