iTechtalk

Quick Search

Go Advanced

Member Login

Not registered? | Forgot Password
 
Register
Welcome
 
iTechtalk > Tutorials > Operating systems » Using Audit Logging to Analyze DHCP Server Behavior
Reply
Old 10-10-2008, 12:10 PM   #1 (permalink)
 
Brivo's Avatar
 
Junior Member
Join Date: Oct 2008
Posts: 11
Smile Using Audit Logging to Analyze DHCP Server Behavior

Using Audit Logging to Analyze DHCP Server Behavior

The DHCP Server service stores an audit log in %SystemRoot%\System32\DHCP. The DHCP Server service bases the name of the audit log file on the current day of the week, as determined by checking the current date and time at the server. For example, when the DHCP server starts, if the current date is Monday, October 8, 2007, the IPv4 audit log file is named DhcpSrvLog-Mon, and the IPv6 audit log file is named DhcpV6SrvLog-Mon. The DHCP Server starts a new log file at midnight and overwrites log files from the previous week.

By default, the DHCP Server service stops audit logging if disk space is less than 20MB or the current log file is larger than one-seventh the maximum allotted space or size for the combined total of all audit logs currently stored on the server. By default, each log file can be a maximum of 10MB. You can change the maximum size by multiplying the desired value by seven (for each day of the week) and storing the value in the HKEY_LOCAL_MACHINE\ System\CurrentControlSet\Services\DHCPServer\Param eters\DhcpLogFilesMaxSize registry value.

Each audit log file begins with a description of the different event codes and the fields in the log file. Therefore, audit log files are self-explanatory. Audit logging is enabled by default.


To Enable or Disable Audit Logging

1. Click Start, click Administrative Tools, and then click DHCP.

2. Expand your server name, right-click either IPv4 or IPv6, and then click Properties.

3. On the General tab, select the Enable DHCP Audit Logging check box, and then click OK.


To Change the Audit Log File Path

1. Click Start, click Administrative Tools, and then click DHCP.

2. Expand your server name, right-click either IPv4 or IPv6, and then click Properties.

3. On the Advanced tab, click Browse to select the audit log file path, and then click OK.
Brivo is offline   Reply With Quote
 
Reply

Bookmarks

Tags
audit, dhcp, logging, server

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
How to analyze the Performance Monitor Logs in Windows Server 2008? Satyakam Windows server/NT/Work Station 1 05-11-2009 09:55 AM
How to audit the user activities on the Computer in Windows Server 2008? Shaurya Windows server/NT/Work Station 1 05-08-2009 06:58 AM
Set default behavior for Autorun in Windows 7 eternity Windows 7 0 04-17-2009 05:36 AM
Analyze tool for Windows Server 2003 Domain Controller raaz Windows server/NT/Work Station 1 03-13-2009 01:30 PM
Configuring Client Behavior When a DHCP Server Is Not Available Servantus Operating systems 0 10-08-2008 09:14 AM


 

Content Relevant URLs by vBSEO 3.3.0