Microsoft DHCP Server CSV Audit Log
Microsoft DHCP Server IPv4 audit log (DhcpSrvLog-<Day>.log, 19-column CSV) as parsed ECS JSON with the native row in event.original: lease and DNS-update traffic of 970 Windows clients in two scopes, about 12,900 rows a day with a working-day peak. Not Windows Event Log or IPv6. Recurring episodes show one laptop churning through three more addresses of its own within minutes before its last DNS registration fails.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/windows-dhcp-audit/generator.yml \
--id windows-dhcp-audit \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| 11 | Renew: an active lease reaches T1 | 30.8% of rows | network |
| 10 | Assign: session start, or reconnect inside a link flap | 14.4% of rows | network |
| 12 | Release: session end, or the disconnect of a link flap | 14.4% of rows | network |
| 30 | DNS Update Request after 55% of assignments and 40% of renewals | 20.2% of rows | network |
| 32 | DNS Update Successful: result of a request, same host and IP | 18.9% of rows | network |
| 31 | DNS Update Failed: result of a request, native error 10054 | 1.3% of rows | network |
Realism Features
- 840 desktops and VDI machines in 10.20.16.0/20 and 130 laptops in 10.20.32.0/22, each with its own set of four addresses in its scope. The sets do not overlap, so an address is never held by two clients.
- Each client has its own sessions: Assign, renewal 0-30 minutes after T1, Release. Session length is lognormal (median 4 h for laptops, 30 h for desktops), the offline gap has a median of 2 h / 50 min, and connects follow an hour-of-day curve high from 08:00 to 17:00 UTC.
- While a client is active, link flaps (Release, then Assign about a minute later, with probability 0.4 another flap a few minutes later) come once per 1.5-4 h for laptops and once per 15-60 h for desktops, less often at night. A reassignment changes the address with probability 0.7 for laptops and 0.2 for desktops, so fast Release-Assign pairs, multi-cycle bursts and address changes occur in background.
- About 12,900 rows a day: 9,000 around the clock and 3,900 on a working-day curve peaking around 12:30 UTC, from about 360 rows an hour at night to about 800 at midday. Renewals and DNS updates dominate the night, connects and flaps the working day.
- DNS request and result follow their Assign or Renew a few seconds apart (median about 5 s), where a real server usually writes them in the same second; about 8% of request and result pairs share one second. A result fails with probability 0.06, or 0.5 within three hours of a failure of the same client. Assign/Renew carry vendor class MSFT 5.0; DNS rows have no MAC, transaction ID 0 and QResult 6.
- Only IDs 10/11/12/30/31/32 are emitted: no lease expiry, NACKs, conflicts, relay, failover, service start/stop, file headers or IPv6. Each client keeps a fixed address set, while a real server reuses addresses between clients, and no lease expires. No correlated native capture of this scenario or of an identified Windows Server build exists.
- Filebeat identity, host and observer MACs and the event.ingested delay are synthetic; log.offset counts emitted rows per UTC date without file headers, and related.ip / related.hosts are added although the Elastic integration pipeline does not set them. Session, flap, DNS and failure rates, the hour curve and the daily volume are synthetic choices.
Sample Output
{
"@timestamp": "2026-09-25T14:28:40+00:00",
"agent": {
"ephemeral_id": "a1b2c3d4-1111-4444-8888-123456789abc",
"id": "a1b2c3d4-1111-4444-8888-123456789abc",
"name": "dhcp-01.corp.example",
"type": "filebeat",
"version": "8.17.0"
},
"data_stream": {
"dataset": "microsoft_dhcp.log",
"namespace": "default",
"type": "logs"
},
"ecs": {
"version": "8.17.0"
},
"elastic_agent": {
"id": "a1b2c3d4-1111-4444-8888-123456789abc",
"snapshot": false,
"version": "8.17.0"
},
"event": {
"action": "dhcp-release",
"agent_id_status": "verified",
"category": [
"network"
],
"code": "12",
"dataset": "microsoft_dhcp.log",
"ingested": "2026-09-25T14:28:41.538596+00:00",
"kind": "event",
"original": "12,09/25/26,14:28:40,Release,10.20.32.189,nb-finance-010.corp.example,0023DFA8FECF,,418295063,0,,,,,,,,,0",
"outcome": "success",
"reason": "A lease was released by a client.",
"timezone": "UTC",
"type": [
"allowed",
"connection"
]
},
"host": {
"ip": [
"10.20.0.10"
],
"mac": [
"02-42-AC-11-00-10"
],
"name": "dhcp-01.corp.example"
},
"input": {
"type": "log"
},
"log": {
"file": {
"path": "C:\\Windows\\System32\\Dhcp\\DhcpSrvLog-Fri.log"
},
"offset": 973827
},
"message": "Release",
"microsoft": {
"dhcp": {
"dns_error_code": "0",
"result": "0",
"result_description": "NoQuarantine",
"transaction_id": "418295063"
}
},
"observer": {
"hostname": "dhcp-01.corp.example",
"ip": [
"10.20.0.10"
],
"mac": [
"02-42-AC-11-00-10"
]
},
"related": {
"hosts": [
"nb-finance-010.corp.example"
],
"ip": [
"10.20.32.189"
]
},
"source": {
"address": "nb-finance-010.corp.example",
"domain": "nb-finance-010.corp.example",
"ip": "10.20.32.189",
"mac": "00-23-DF-A8-FE-CF"
},
"tags": [
"preserve_original_event",
"microsoft_dhcp"
]
}Parameters
| Parameter | Default | Description |
|---|---|---|
| server_name | dhcp-01.corp.example | DHCP server name (host.name, observer.hostname, agent.name) |
| server_ip | 10.20.0.10 | DHCP server IPv4 address |
| lease_renew_minutes | 240 | T1 in minutes, 60-5,760; the modeled lease lasts twice T1 |
| anomaly_mode | true | Recurring episodes mixed with background; false for background only |
| anomaly_interval_hours | 24 | Episode interval in hours, 4-8,760 |
Related Generators
Cisco ASA Firewall
Cisco ASA adaptive security appliance syslog — TCP/UDP/ICMP connection lifecycle, ACL permit/deny decisions, NAT translations, VPN tunnel events, and failover status messages.
Check Point Security Gateway
Check Point Security Gateway SmartLog — 8 software blades including Firewall, IPS, Application Control, URL Filtering, Anti-Bot, Anti-Virus, Threat Emulation, and Identity Awareness.
Network Traffic (Continent-Level Geo)
Network traffic events enriched with continent-level geographic information. Models cross-continent and same-continent flows for both inbound and outbound directions, with realistic allow/deny outcomes based on geographic policy.