[Kea-users] Kea DHCP forensic logging

Jim Springsteen jim.springsteen at southslope.com
Tue Jan 21 21:33:51 UTC 2025


Darren,

I appreciate your response.  I did follow the example and this is what I have in my config:
    "hooks-libraries": [
       {
           "library": "/usr/lib/x86_64-linux-gnu/kea/hooks/libdhcp_legal_log.so",
                "parameters": {
                    "path": "/var/log/kea",
                    "base-name": "kea-forensic4"
               }
       },
But in my kea-forensic4 log, I have this entry:
"identified by circuit-id: 00:04:00:00:00:06 and remote-id: 00:06:ac:3a:67:d6:de:f2"

I have confirmed via tcpdump that the server is receiving a string of characters as the circuit ID from my access gear.

I am not sure what I am missing.

Thanks,
Jim Springsteen
Data Administrator

jim.springsteen at southslope.com<mailto:jim.springsteen at southslope.com> | southslope.com<http://www.southslope.com/>
319-626-2211<tel:3196262211> main | 319-665-5334<tel:3196655334> direct
980 North Front St, North Liberty, IA 52317

[https://www.southslope.com/wp-content/uploads/2019/12/SouthSlope_Email_Logo.png]<https://www.southslope.com/>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.isc.org/pipermail/kea-users/attachments/20250121/ad7af89a/attachment.htm>


More information about the Kea-users mailing list