Pre Configuration

Before installing or configuring Windows, you need to select the DHCP and DNS Server channels in Logpoint Agent in order to send Windows DHCP and DNS logs to your Logpoint Agent.

DHCP and DNS Servers record events in Windows Event Logs under event log channels like DHCP-Server and DNS-Server. These channels are in your server’s Event Viewer.

You must configure a static IP address to install DHCP and DNS Servers. Go to Set Static IP Address to learn how to do it.

Disclaimer

The documentation here are just examples and were made on Windows 11. If we mention specific software or operating systems, it’s only to explain things better.

Configuring DHCP server

DHCP log records DHCP Server actions, detailing IP address assignments and configurations for client devices. The log provides information about assignment time, IP and MAC addresses and lease duration, which you can analyze through the LP_Windows DHCP dashboard.

Installing DHCP server

  1. Go to Start >> Server Manager and click Manage.

  2. Click Add Roles and Features.

_images/DHCP1.png
  1. Click Next upto Server Roles and select DHCP Server.

_images/DHCP2.png
  1. Click Add Features.

_images/DHCP3.png
  1. Click Next upto Confirmation and click Install.

_images/DHCP4.png
  1. Click Complete DHCP configuration.

_images/DHCP5.png

Note

If you click Close by mistake, a notification appears on the left of Manage. Click Notification and Complete DHCP configuration to complete post deployment configuration.

_images/DHCP6.png
  1. Click Next to select Authorization and click Commit.

_images/DHCP7.png
  1. Click Close.

Enable DHCP Audit Logging

  1. Go to Start >> Server Manager and click Tools.

  2. Click DHCP to open the DHCP management console.

_images/DHCP8.png
  1. Right click the DHCP server drop-down. Your server is listed here. For example, ws2k19-dc01.mylab.local.

_images/DHCP_9.png

If you don’t have a green check mark on respective protocol name (IPv4 and IPv6).

3.1. Right click the DHCP server.

3.2. Click Authorize

_images/DHCP10.png

Authorizing the protocols

  1. Right click IPv4 and click Properties.

_images/DHCP11.png
  1. In General, select Enable DHCP audit logging.

  2. Click OK.

_images/DHCP12.png

To change the default location path of logs,

  1. Click Advanced.

  1. Browse to your Audit log file path or enter the path. The file path is required for the configuration of Logpoint Agent File Collection in Logpoint.

  2. Click OK.

Enable DHCP Admin and Operational Logging

  1. Open Event Viewer.

  2. Go to Applications and Services Logs >> Microsoft >> Windows.

  3. Click DHCP-Server drop-down.

    4.1 For DHCP Admin logs, right click Microsoft-Windows-DHCP Server Events/Admin.

    For DHCP Operational logs, right click Microsoft-Windows-DCHP Server Events/Operational.

    _images/dhcpadmnopre.png

    3.2 Click Properties.

    3.3 In General, select Enable logging.

    Important

    You must note the Full Name of the event channel. It is required while you configure Logpoint Agent later.

    3.4 Click Apply to save the configuration.

    3.5 Click OK.

    _images/foropera.png

    Enabling DHCP Admin Logging

Configuring DNS server

DNS logs are maintained by DNS (Domain Name System) servers to record server activity, documenting both queries and responses. The logs provide information about the queries made to the DNS server and the responses the server gave, which you can analyze through the LP_Windows DNS dashboard. The logs contain details like query time, the domain name requested and the client’s IP address.

Installing DNS Server

  1. Go to Start >> Server Manager and click Manage.

  2. Click Add Roles and Features.

  3. Click Next upto Server Selection. In Server Pool, make sure correct server is selected.

  4. Click Next to Server Roles and select DNS Server.

  5. Click Add Features.

  6. Click Next upto Confirmation and click Install.

  7. Click Close.

Enable DNS Debug Logging

  1. Go to Start >> Server Manager and click Tools.

  2. Click DNS.

  3. Right click the DNS server name and click Properties.

_images/DEBUG1.png
  1. In Debug Logging, select Log packets for debugging.

  2. Enter your File path and name to save the logs at. For example, C:\logpoint.

  3. Click Apply to save the configuration.

  4. Click OK.

_images/DEBUG2.png

Enable DNS Audit Logging

  1. Open Event Viewer.

  2. Go to Applications and Services Logs >> Microsoft >> Windows and click DNS-Server drop-down.

  3. Right click Audit and click Properties.

  4. In General, select Enable logging. You must note the Full Name of the event channel required while configuring Logpoint Agent.

Important

The Log Path is required while configuring NXLog.

  1. Click Apply to save the configuration.

  2. Click OK.

_images/dnsaudit.png

After receiving DHCP and DNS logs in the provided path, you must configure NXLog to forward logs to Logpoint. Go to NXLog Sample Configuration to learn how to configure.

Important

Ensure the File path provided in the NXLog Sample Configuration is one you enter for DHCP and DNS Audit Logging.


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support