DHCP Lease Log
Definition
A record maintained by a Dynamic Host Configuration Protocol server that maps each IP address assignment to the requesting device's MAC address, the lease start and end times, and often the device hostname. Used in investigations to determine which device held a given IP address at a specific time.
- Maintained by
- DHCP server on the network
- Maps
- IP address to MAC address
- Also records
- Lease start/end time, hostname
- Investigative use
- Attribute an IP to a device at a time
Common questions
Why can't a DHCP lease log alone identify a specific person?+
It links an IP address to a device's MAC address and a time window, not to a user identity. Investigators still need to tie that device to a person through other evidence such as device seizure, account logins, or physical possession.
How long are DHCP lease logs typically retained?+
Retention varies widely by network operator and is often short, sometimes days, because lease tables are operational data rather than security logs. Investigators usually need to request preservation quickly once a relevant IP and timeframe are identified.
Related terms
- Anchor Event
- A log entry that can be identified with high confidence across two or more log sources, used to verify relative clock offsets...
- Clock Skew
- The difference between a device's local clock and a trusted reference time such as UTC. Skew accumulates due to hardware drift, timezone...
- Intrusion Detection System (IDS)
- A network or host-based monitoring system that analyses traffic or system behaviour against a rule set (signature-based) or a statistical baseline (anomaly-based)...
- Log Normalisation
- The conversion of log entries from their native format into a common schema, typically a structured record with a corrected UTC timestamp,...
- NAT (Network Address Translation)
- A mechanism by which a router replaces private source IP addresses with a single public IP address before forwarding packets to the...
- NetFlow
- A network protocol (originally Cisco, now standardised as IPFIX under RFC 7011) that records metadata about IP traffic flows: source and destination...
- PCAP (Packet Capture)
- A file format (and the process of creating it) that records every byte of every network packet passing a capture point, including...
- RADIUS Log
- An authentication, authorisation, and accounting record produced by a Remote Authentication Dial-In User Service server. Each entry records the username, authenticating device...
- Session Tuple
- The five-element identifier for a network session: source IP, source port, destination IP, destination port, and protocol. The session tuple is the...
- Syslog
- A standardised protocol (RFC 5424) for transmitting log messages from network devices to a centralised log server. Routers, switches, firewalls, and servers...
Explained in these topics
- Network Evidence Sources and Their Forensic Value
- Reconstructing a Network Timeline from Multiple SourcesA record maintained by a DHCP server that maps an IP address to the MAC address (and optionally the hostname) of the device that held that lease during a speci...