<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ingest DHCP logs using XDR collector in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/519527#M3060</link>
    <description>&lt;P&gt;Hi Peter,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had this issue with the the collector as well and thought it was the yml file also.&lt;/P&gt;
&lt;P&gt;I thought when you install the collector it installs the file beat service with it but it dosent.&lt;/P&gt;
&lt;P&gt;I had to go to C: &amp;gt; Program data&amp;gt;XDR Collector &amp;gt; Content &amp;gt; filebeat-windows-x86_64&amp;nbsp; run the install-service-filebeat from powershell and then start the service from powershell as well.&lt;/P&gt;
&lt;P&gt;Once i did that it worked for me.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 28 Oct 2022 11:15:38 GMT</pubDate>
    <dc:creator>KarlHalpin</dc:creator>
    <dc:date>2022-10-28T11:15:38Z</dc:date>
    <item>
      <title>Ingest DHCP logs using XDR collector</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/510177#M2401</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am having issues with ingesting DHCP log from our DCs. We are using the XDR Collector app. I suspect that the issue is with the filebeat.yml file but cannot figure out what the problem is. I have tried and followed the guide below and copy-paste the example code but no logs are showing up. The yml has been checked and the syntax is correct.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/cortex-xdr-collectors/add-a-xdr-collector-profile/ingest-logs-from-windows-dhcp#id4506c349-4398-4c76-bcfc-8ef16f7c0050_id4862f7d3-1e69-4432-abac-8de40c656b86" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/cortex-xdr-collectors/add-a-xdr-collector-profile/ingest-logs-from-windows-dhcp#id4506c349-4398-4c76-bcfc-8ef16f7c0050_id4862f7d3-1e69-4432-abac-8de40c656b86&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there anyone that has successfully managed to ingest those logs?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 18:43:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/510177#M2401</guid>
      <dc:creator>PeterBengtslin</dc:creator>
      <dc:date>2024-04-18T18:43:54Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest DHCP logs using XDR collector</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/510227#M2403</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18507"&gt;@PeterBengtslin&lt;/a&gt;&amp;nbsp;have you checked if the path to the DHCP logs are valid? Is the issue persistent if you use a filebeat collector?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 01:58:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/510227#M2403</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-07-29T01:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest DHCP logs using XDR collector</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/511301#M2500</link>
      <description>&lt;DIV&gt;
&lt;DIV&gt;
&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192661"&gt;@bbarmanroy&lt;/a&gt;&amp;nbsp;Thank you for your reply. The path is valid but there is something in the filebeat configuraion that is causing it to inactivate the service. I have been doing some labs on this and found out that this configuration is giving an acceptable result:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;filebeat.inputs:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;-&amp;nbsp;type:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;log&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;enabled:&amp;nbsp;true&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;paths:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;-&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;c:\Windows\System32\dhcp\DhcpSrvLog*.log&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;processors:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;-&amp;nbsp;add_fields:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;fields:&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;vendor:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"microsoft"&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;product:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"dhcp"&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;-&amp;nbsp;drop_event.when.not.regexp.message:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"^[0-9]+,.*"&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;-&amp;nbsp;dissect:&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;tokenizer:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"%{id},%{date},%{time},%{description},%{ipAddress},%{hostName},%{macAddress},%{userName},%{transactionID},%{qResult},%{probationTime},%{correlationID},%{dhcid},%{vendorClassHex},%{vendorClassASCII},%{userClassHex},%{userClassASCII},%{relayAgentInformation},%{dnsRegError}"&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;This will store the information in dataset microsoft_dhcp_raw and the content will be split into fields defined in the tokenizer statement.&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Best regards,&lt;/DIV&gt;
&lt;DIV&gt;Peter&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 09 Aug 2022 12:27:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/511301#M2500</guid>
      <dc:creator>PeterBengtslin</dc:creator>
      <dc:date>2022-08-09T12:27:41Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest DHCP logs using XDR collector</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/517996#M3026</link>
      <description>&lt;P&gt;Hi, I found the problem causing service inactivation. There is a \n inserted between "tokenizer:" and its parameter that has to be removed. The result has to be on one line.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Oct 2022 10:55:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/517996#M3026</guid>
      <dc:creator>Honza_Linhart</dc:creator>
      <dc:date>2022-10-15T10:55:17Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest DHCP logs using XDR collector</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/519527#M3060</link>
      <description>&lt;P&gt;Hi Peter,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had this issue with the the collector as well and thought it was the yml file also.&lt;/P&gt;
&lt;P&gt;I thought when you install the collector it installs the file beat service with it but it dosent.&lt;/P&gt;
&lt;P&gt;I had to go to C: &amp;gt; Program data&amp;gt;XDR Collector &amp;gt; Content &amp;gt; filebeat-windows-x86_64&amp;nbsp; run the install-service-filebeat from powershell and then start the service from powershell as well.&lt;/P&gt;
&lt;P&gt;Once i did that it worked for me.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Oct 2022 11:15:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/519527#M3060</guid>
      <dc:creator>KarlHalpin</dc:creator>
      <dc:date>2022-10-28T11:15:38Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest DHCP logs using XDR collector</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/575465#M6004</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;I created XDR collector package and installed it on my windows server. But it does not show up on Administration tab where i am supposed to see all xdr collector agent lists. What can be the reason for this?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 07:15:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/575465#M6004</guid>
      <dc:creator>JahidAliyev</dc:creator>
      <dc:date>2024-02-02T07:15:09Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest DHCP logs using XDR collector</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/575483#M6006</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/274228"&gt;@JahidAliyev&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this looks like communication issue - server (XDR collector on the server) is not able to reach XDR management console. Try to check FW outbound rules (local FW on the server and any FW in the path to XDR management).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 10:11:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/575483#M6006</guid>
      <dc:creator>Honza_Linhart</dc:creator>
      <dc:date>2024-02-02T10:11:57Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest DHCP logs using XDR collector</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/575484#M6007</link>
      <description>&lt;P&gt;When I am in organization network, it cannot communicate. When I am using my own internet, it directly connected. If I switch to my organization network, will it be disconnected again?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 10:13:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/575484#M6007</guid>
      <dc:creator>JahidAliyev</dc:creator>
      <dc:date>2024-02-02T10:13:41Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest DHCP logs using XDR collector</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/575485#M6008</link>
      <description>&lt;P&gt;And, do I need to write parsing rules or Cortex XDR will automatically bring DHCP logs under "dhcp" dataset?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 10:15:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/575485#M6008</guid>
      <dc:creator>JahidAliyev</dc:creator>
      <dc:date>2024-02-02T10:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest DHCP logs using XDR collector</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/575486#M6009</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/241246"&gt;@Honza_Linhart&lt;/a&gt;&amp;nbsp;If you answer these two, I would be so happy&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 10:16:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/575486#M6009</guid>
      <dc:creator>JahidAliyev</dc:creator>
      <dc:date>2024-02-02T10:16:26Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest DHCP logs using XDR collector</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/575492#M6010</link>
      <description>&lt;P&gt;For proper function, you need XDR collector connected to XDR management console all the time. You're using this connection to ingest data from on-premise server to cloud data lake. So yes, if you put it back to the network that doesn't allow connection, it will be disconnected again.&lt;/P&gt;
&lt;P&gt;If you will have your XDR collector up and connected, use config file mentioned in this thread and you will get your DHCP logs into new dataset in Cortex XDR. There is no need to write your own parsers.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 11:23:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/575492#M6010</guid>
      <dc:creator>Honza_Linhart</dc:creator>
      <dc:date>2024-02-02T11:23:11Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest DHCP logs using XDR collector</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/575493#M6011</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/241246"&gt;@Honza_Linhart&lt;/a&gt;&amp;nbsp;Surprisingly, when I connect back to my organzition network, it does not become disconnected.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I use this as config file, what will be the name of dataset if I want to look at these logs on queries?&lt;/P&gt;
&lt;P&gt;And, is it okey to install this collector agent on any windows or we need to install it on DC and DHCP server? Because I simply installed it on usual endpoint which is not DC or DHCP server.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 11:31:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ingest-dhcp-logs-using-xdr-collector/m-p/575493#M6011</guid>
      <dc:creator>JahidAliyev</dc:creator>
      <dc:date>2024-02-02T11:31:31Z</dc:date>
    </item>
  </channel>
</rss>

