# DHCP information add to other log files

**URL:** <https://discuss.elastic.co/t/dhcp-information-add-to-other-log-files/37989>\
**Category:** Elasticsearch\
**Created:** [December 26, 2015, 7:38pm UTC](https://discuss.elastic.co/t/dhcp-information-add-to-other-log-files/37989 "2015-12-26T19:38:36Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hans](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Hans](https://discuss.elastic.co/u/Hans)\
**Post date:** [December 26, 2015, 7:38pm UTC](https://discuss.elastic.co/t/dhcp-information-add-to-other-log-files/37989/1 "2015-12-26T19:38:36Z")

</div>

Hi All, I would like to use the information from the DHCP server to add additional information to the other log files. Not sure where to best do this in the ELK stack however assume Elasticsearch would be it. So what I have is the one log file from the DHCP server that contains:  
IP Address  
Username  
Serial number  
IP assignment state  
Etc.  
Now I have numerous files from the DNS and Proxy where I would like to use the IP address to add the username, serial number, etc. to the DNS information and proxy information. The DHCP server has been modified to also add information “IP assignment state“ when the IP is assigned and when it is disconnected as the leases are 0 so within seconds a different user can use the same IP address.  
So is it possible to use the DHCP file to add the Username, serial number, etc. to the DNS and Proxy log files using the IP address information when assigned and when assignment has been terminated?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 26, 2015, 8:45pm UTC](https://discuss.elastic.co/t/dhcp-information-add-to-other-log-files/37989/2 "2015-12-26T20:45:07Z")

</div>

You'd have to write something to parse the DHCP file and apply it during log ingestion. The Logstash translate filter would be a good place to start looking.

---

<div class="post-metadata">

**Author:** ![Hans](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Hans](https://discuss.elastic.co/u/Hans)\
**Post date:** [December 27, 2015, 4:47am UTC](https://discuss.elastic.co/t/dhcp-information-add-to-other-log-files/37989/3 "2015-12-27T04:47:12Z")

</div>

Why I thought Elasticsearch is the place to do this is due to the DHCP server only sends information as it happens. So it can be days where the IP is assigned, how would logstash maintain such data? Is Elasticsearch not able to maintain this data only logstash?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 27, 2015, 6:29am UTC](https://discuss.elastic.co/t/dhcp-information-add-to-other-log-files/37989/4 "2015-12-27T06:29:05Z")

</div>

How would it do that though?

---

<div class="post-metadata">

**Author:** ![Hans](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Hans](https://discuss.elastic.co/u/Hans)\
**Post date:** [December 27, 2015, 7:16am UTC](https://discuss.elastic.co/t/dhcp-information-add-to-other-log-files/37989/5 "2015-12-27T07:16:15Z")

</div>

Not sure, however will logstash be able to do this?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 27, 2015, 7:34am UTC](https://discuss.elastic.co/t/dhcp-information-add-to-other-log-files/37989/6 "2015-12-27T07:34:53Z")

</div>

Like I said, something like the translate filter.  
But you'd have to build it, it's not anything currently available that I know of.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:28pm UTC](https://discuss.elastic.co/t/dhcp-information-add-to-other-log-files/37989/7 "2017-07-05T23:28:30Z")

</div>


