- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
Can lease history be exported to syslog or siem?
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-03-2018 04:57 AM
HI Bloxers!
This is not at all covered in the documentation, except for using API to export the logs.
Is this possible?
The customer is not using reporter either, which I know holds more than the default of 100k entries.
But we need to store past lease history more than 100k entries to syslog in a format which can be later viewed etc.
Thanks.
Re: Can lease history be exported to syslog or siem?
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-03-2018 07:33 AM
The Infoblox Reporting solution is ideal for this, but certainly not a requirement. DHCP activity is logged in the syslog and yes, that can be sent to an external syslog server. Refer to the section titled "Using a Syslog Server" in the NIOS Administrators Guide for more details regarding this.
Alternatively, the Infoblox Outbound API solution can be used to integrate with a SIEM. For information regarding the Outbound API feature (which does require a separate 'ecosystem' license), refer to the chapter titled "Ecosystem - Outbound Notifications" in the NIOS Administrators Guide.
The above is useful for real-time activities. For the DHCP Lease History data, there are export mechanisms that will allow you to export this data in CSV format. You can use the Grid Manager GUI to do this but for continuous management of the lease history data, you would find it more appropriate to use the API. Details can be found in the section titled "Exporting Lease Records" in the NIOS Administrators Guide. In addition to the Infoblox WAPI Reference Guide, you may also find the following community forum post helpful with how to use the API for this process:
Regards,
Tony
Re: Can lease history be exported to syslog or siem?
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-10-2019 05:52 AM
You may also want to take a look at this: