Abstract
Learn more about the Windows DHCP Standard Collector and content pack integrations in Cortex XSIAM.
You can configure collecting Windows DHCP logs using a Standard Collector or with a content pack integration:
Windows DHCP vendor | Description |
|---|---|
Standard Collector (basic) overview | Forward logs to Cortex XSIAM from Windows DHCP logs using Elasticsearch Filebeat with the Windows DHCP data source. |
Link to Standard Collector instructions | |
Link to content pack details | The Microsoft DHCP content pack processes and normalizes audit logs from the Dynamic Host Configuration Protocol (DHCP) service for security analysis in Cortex XSIAM. It includes modeling Rules and parsing rules for events collected using the XDR Collector via the |