Ad Widget

Collapse

Windows DHCP Server: collecting events of blacklisted/whitelisted devices

Collapse
This topic has been answered.
X
X
 
  • Time
  • Show
Clear All
new posts
  • fabiosupryx
    Junior Member
    • Jun 2025
    • 5

    #1

    Windows DHCP Server: collecting events of blacklisted/whitelisted devices

    Hello folks!

    I'll try to be brief: Windows Server has a log called 'Microsoft-Windows-Dhcp-Server/FilterNotifications' that records activity within the scope when, for example, blacklisted devices attempt to join the LAN. When this happens, it generates Event ID 20094, 20096, or 20099, which refer to explicit or implicit denials. Attached are some screenshots for better understanding.

    Click image for larger version

Name:	image.png
Views:	120
Size:	140.8 KB
ID:	503766

    As you can see in the screenshot above, I'm using the 'eventlog' filter, specifying the event source and, of course, performing active checking as recommended in the documentation. In the example above, Event 20096 refers to a device that was denied an IP because it is explicitly on the blacklist. However, unfortunately, I have not been successful in collecting this data, and I can't find the reason why.

    I went ahead and corrected the way the event source was referenced in the filter, and the error below no longer appears in the Zabbix agent log.

    Click image for larger version

Name:	image.png
Views:	66
Size:	105.8 KB
ID:	503767

    I tried changing the event source using 'Provider' and 'Channel', but without success. I’d appreciate it if you could help figure out what’s wrong. Thank you very much!

    Click image for larger version

Name:	image.png
Views:	69
Size:	36.1 KB
ID:	503768

    ​​
  • Answer selected by Donkey at 17-06-2025, 14:26.
    fabiosupryx
    Junior Member
    • Jun 2025
    • 5

    Well... case closed: replacing the agent and using the agent2 did the trick.

    Comment

    • fabiosupryx
      Junior Member
      • Jun 2025
      • 5

      #2
      Well... case closed: replacing the agent and using the agent2 did the trick.

      Comment

      Working...