none
How to capture MAC address & other details in DHCP audit logs (Server 2012 R2 & Server 2016) RRS feed

  • Question

  • Hi,

    When i went to DHCP Log file (DhcpSrvLog-Fri.log) i saw most of the fields empty. How can i enable server to audit these details. I consider the performance degradation after enabling too much of logging, but atleast i should be able to see MAC Address, UserName, verdor id, userid and relayagent. can someone put some light on it?

    Server 2012 R2 & Server 2016

    preview of DHCP Log File in Excel (DhcpSrvLog-Fri.log)


    Thanks, Rishi Pandit.

    Wednesday, March 29, 2017 10:24 AM

Answers

All replies

  • Hi Rishi,

    To enable DHCP audit, please open DHCP server management, and right-click IPv4, click properties, and check Enable DHCP log audit.

    Please reference picture below for further understanding:

    Best Regards

    John


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Thursday, March 30, 2017 10:01 AM
  • Yes, i do have audit logging enabled on my dhcp server but even after that i am not getting MAC Address, username & other info. Please refer to the snapshot attached in question.

    Thanks, Rishi Pandit.

    Thursday, March 30, 2017 10:07 AM
  • Any suggestions ?

    Thanks, Rishi Pandit.

    Wednesday, April 5, 2017 12:30 PM
  • Hi Rishi,

    Sorry for reply later.

    You could try to deploy IPAM server to achieve the goal.

    Please check link below for further understanding:

    IP Address Tracking

    https://technet.microsoft.com/en-us/library/jj878332(v=ws.11).aspx

    Best Regards

    John


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    • Marked as answer by Rishi Pandit Monday, June 26, 2017 2:35 PM
    Thursday, April 6, 2017 6:31 AM