Hi Team,
I have on boarded DHCP logs into ELK and looking for SIEM detection anomaly for DHCP logs. I didn't seen anything dashboard related for DHCP logs in SIEM
DHCP logs example :-1
Fields:
ID,Date,Time,Description,IP Address,Host Name,MAC Address,User Name, TransactionID, QResult,Probationtime, CorrelationID,Dhcid,VendorClass(Hex),VendorClass(ASCII),UserClass(Hex),UserClass(ASCII),RelayAgentInformation,DnsRegError.
logs :-
24,11/25/16,00:00:36,Database Cleanup Begin,,,,,0,6,,,,,,,,,0
30,11/25/16,00:00:36,DNS Update Request,10.115.0.70,HOSTNAME,,,0,6,,,,,,,,,0
I have converted all fields according ECS format in logstash
"%{DATA:id},%{DATE_US:date},(?%{HOUR}:%{MINUTE}:%{SECOND}),%{DATA:description},%{IPV4:[source][ip]},%{DATA:[source][hostname]},%{DATA:mac},%{DATA:[user][name]},%{INT:[transaction][id]},%{INT:[q][result]},%{DATA:[probation][time]},%{DATA:[correlation][id]},%{DATA:dhcid},%{DATA:[vendorclass][hex]},%{DATA:[vendorClass][ascii]},%{DATA:[userclass][hex]},%{DATA:[userclass][ascii]},%{DATA:[relayagen][information]},%{INT:[dns][reg][error]}"}
Can you please suggest me is DHCP logs will work for SIEM module?