Hub
Network

Microsoft DHCP Server CSV Audit Log

Microsoft DHCP Server IPv4 audit log (DhcpSrvLog-<Day>.log, 19-column CSV) as parsed ECS JSON with the native row in event.original: lease and DNS-update traffic of 970 Windows clients in two scopes, about 12,900 rows a day with a working-day peak. Not Windows Event Log or IPv6. Recurring episodes show one laptop churning through three more addresses of its own within minutes before its last DNS registration fails.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/windows-dhcp-audit/generator.yml \
  --id windows-dhcp-audit \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
11Renew: an active lease reaches T130.8% of rowsnetwork
10Assign: session start, or reconnect inside a link flap14.4% of rowsnetwork
12Release: session end, or the disconnect of a link flap14.4% of rowsnetwork
30DNS Update Request after 55% of assignments and 40% of renewals20.2% of rowsnetwork
32DNS Update Successful: result of a request, same host and IP18.9% of rowsnetwork
31DNS Update Failed: result of a request, native error 100541.3% of rowsnetwork

Realism Features

  • 840 desktops and VDI machines in 10.20.16.0/20 and 130 laptops in 10.20.32.0/22, each with its own set of four addresses in its scope. The sets do not overlap, so an address is never held by two clients.
  • Each client has its own sessions: Assign, renewal 0-30 minutes after T1, Release. Session length is lognormal (median 4 h for laptops, 30 h for desktops), the offline gap has a median of 2 h / 50 min, and connects follow an hour-of-day curve high from 08:00 to 17:00 UTC.
  • While a client is active, link flaps (Release, then Assign about a minute later, with probability 0.4 another flap a few minutes later) come once per 1.5-4 h for laptops and once per 15-60 h for desktops, less often at night. A reassignment changes the address with probability 0.7 for laptops and 0.2 for desktops, so fast Release-Assign pairs, multi-cycle bursts and address changes occur in background.
  • About 12,900 rows a day: 9,000 around the clock and 3,900 on a working-day curve peaking around 12:30 UTC, from about 360 rows an hour at night to about 800 at midday. Renewals and DNS updates dominate the night, connects and flaps the working day.
  • DNS request and result follow their Assign or Renew a few seconds apart (median about 5 s), where a real server usually writes them in the same second; about 8% of request and result pairs share one second. A result fails with probability 0.06, or 0.5 within three hours of a failure of the same client. Assign/Renew carry vendor class MSFT 5.0; DNS rows have no MAC, transaction ID 0 and QResult 6.
  • Only IDs 10/11/12/30/31/32 are emitted: no lease expiry, NACKs, conflicts, relay, failover, service start/stop, file headers or IPv6. Each client keeps a fixed address set, while a real server reuses addresses between clients, and no lease expires. No correlated native capture of this scenario or of an identified Windows Server build exists.
  • Filebeat identity, host and observer MACs and the event.ingested delay are synthetic; log.offset counts emitted rows per UTC date without file headers, and related.ip / related.hosts are added although the Elastic integration pipeline does not set them. Session, flap, DNS and failure rates, the hour curve and the daily volume are synthetic choices.

Sample Output

{
  "@timestamp": "2026-09-25T14:28:40+00:00",
  "agent": {
    "ephemeral_id": "a1b2c3d4-1111-4444-8888-123456789abc",
    "id": "a1b2c3d4-1111-4444-8888-123456789abc",
    "name": "dhcp-01.corp.example",
    "type": "filebeat",
    "version": "8.17.0"
  },
  "data_stream": {
    "dataset": "microsoft_dhcp.log",
    "namespace": "default",
    "type": "logs"
  },
  "ecs": {
    "version": "8.17.0"
  },
  "elastic_agent": {
    "id": "a1b2c3d4-1111-4444-8888-123456789abc",
    "snapshot": false,
    "version": "8.17.0"
  },
  "event": {
    "action": "dhcp-release",
    "agent_id_status": "verified",
    "category": [
      "network"
    ],
    "code": "12",
    "dataset": "microsoft_dhcp.log",
    "ingested": "2026-09-25T14:28:41.538596+00:00",
    "kind": "event",
    "original": "12,09/25/26,14:28:40,Release,10.20.32.189,nb-finance-010.corp.example,0023DFA8FECF,,418295063,0,,,,,,,,,0",
    "outcome": "success",
    "reason": "A lease was released by a client.",
    "timezone": "UTC",
    "type": [
      "allowed",
      "connection"
    ]
  },
  "host": {
    "ip": [
      "10.20.0.10"
    ],
    "mac": [
      "02-42-AC-11-00-10"
    ],
    "name": "dhcp-01.corp.example"
  },
  "input": {
    "type": "log"
  },
  "log": {
    "file": {
      "path": "C:\\Windows\\System32\\Dhcp\\DhcpSrvLog-Fri.log"
    },
    "offset": 973827
  },
  "message": "Release",
  "microsoft": {
    "dhcp": {
      "dns_error_code": "0",
      "result": "0",
      "result_description": "NoQuarantine",
      "transaction_id": "418295063"
    }
  },
  "observer": {
    "hostname": "dhcp-01.corp.example",
    "ip": [
      "10.20.0.10"
    ],
    "mac": [
      "02-42-AC-11-00-10"
    ]
  },
  "related": {
    "hosts": [
      "nb-finance-010.corp.example"
    ],
    "ip": [
      "10.20.32.189"
    ]
  },
  "source": {
    "address": "nb-finance-010.corp.example",
    "domain": "nb-finance-010.corp.example",
    "ip": "10.20.32.189",
    "mac": "00-23-DF-A8-FE-CF"
  },
  "tags": [
    "preserve_original_event",
    "microsoft_dhcp"
  ]
}

Parameters

ParameterDefaultDescription
server_namedhcp-01.corp.exampleDHCP server name (host.name, observer.hostname, agent.name)
server_ip10.20.0.10DHCP server IPv4 address
lease_renew_minutes240T1 in minutes, 60-5,760; the modeled lease lasts twice T1
anomaly_modetrueRecurring episodes mixed with background; false for background only
anomaly_interval_hours24Episode interval in hours, 4-8,760

Related Generators