How to forward DHCP logs to syslog server (SIEM)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

How to forward DHCP logs to syslog server (SIEM)

L0 Member

Does anyone know how to set up forwarding of DHCP logs (leases being issued mainly) from a PAN device operating a DHCP server to a SIEM via syslog? I've already configured a log forwarding profile but I'm not seeing the appropriate DHCP lease logs in my SIEM.

3 REPLIES 3

L4 Transporter

Are you sending the system logs to the syslog server?

https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Forward-System-Logs-to-Syslog-Ser...

Are receiving other logs than the DHCP ones?

 

Regards,

Gerardo.

L0 Member

Hello

 

I also need help with the same issue, how can i forward DHCP lease info to SEIM/syslog server

Hi @ReimoS ,

DHCP lease logs are subtype of system logs. To forward system logs to syslog you need:

1. Create syslog server profile for your SIEM collector

2. Config firewall to forward system logs to syslog by Device -> Log Settings -> System Logs

3. Optionally you can configure log filter to forward only DHCP related logs.

  • 4479 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!