Microsoft DHCP
You can integrate Microsoft DHCP servers with Sophos XDR so that they send data to Sophos for analysis.
This page gives you an overview of the integration.
Microsoft DHCP Server product overview
Microsoft DHCP Server is the DHCP role in Windows Server that automatically assigns IP addresses and related network configuration, such as subnet mask, default gateway, and DNS, to clients from a centrally managed address pool, with audit logging of lease assignments and renewals.
What we ingest
A Sophos XDR data collector accepts Microsoft DHCP audit logs in a comma-delimited format, forwarded from your Windows DHCP servers via syslog (Snare or NXLog). The following log categories are collected:
- DHCP activity: DHCP server audit-log lease events.
Event and data types
We ingest the following event and data types from Microsoft DHCP servers:
- DHCP activity: DHCP server audit-log lease events, such as assignments, renewals, and releases, including the IP address, hostname, MAC address, and action. Normalized to DHCP telemetry.
Data provided by this integration
Data provided by Microsoft DHCP servers gets normalized to the following schemas:
dhcp
For more information about using schemas in Data Lake Search, see Schemas and logical types.