How can we correlate the logs from switches and DHCP to obtain a mapping between the Network Port of the switch and the assigned IP address of the device connected to that network port.
I see that the only common element between these two device sources is the MAC address. However, I’m unable to boil down to the correlation rule that can help me fetch this mapping. Can anyone kindly help me out on this?
This usecase will help network admins (doubling as security admins) to identify the network ports that a device is connected to if a ip address is known