Microsoft DHCP
This pack includes Cortex XSIAM content.
Configuration on Server Side
- Start the DHCP administration tool (go to Start → Programs → Administrative Tools, and click DHCP).
- Right-click the DHCP server, and select Properties from the context menu.
- Select the General tab.
- Select the Enable DHCP audit logging checkbox.
- Click OK.
Note:
Time parsing is supported only when the below fields have the mentioned formats:
- date - MM/dd/yy (01/10/21)
- time - hh:mm:ss (10:00:00)
- timezone - +|-nn:nn (+03:00)
Collect Events from Vendor
In order to use the collector, use the XDRC (XDR Collector) option.
XDRC (XDR Collector)
To create or configure the Filebeat collector, use the information described here and here.
You can configure the vendor and product by replacing [vendor]_[product]_raw with microsoft_dhcp_raw.
As cortex XSIAM provides YAML template for DHCP, you can use the following steps to create a collection profile:
In XSIAM, select Settings → Configurations → XDR Collectors → Profiles → +Add Profile → Windows.
Select Filebeat profile or Winlogbeat profile, then click Next.
Configure the General Information parameters:
Profile Name — Specify a unique Profile Name to identify the profile. The name can contain only letters, numbers, or spaces, and must be no more than 30 characters. The name you choose will be visible from the list of profiles when you configure a policy.
Add description here—(Optional) To provide additional context for the purpose or business reason that explains why you are creating the profile, specify a profile description.
Configure the settings for the profile selected in Step 2 - To add the "DHCP" template, select it and click Add.