Skip links
Unified DNS, DHCP IPAM Observability

Unified DNS, DHCP, and IPAM Observability at Scale

Unified DNS, DHCP, and IPAM Observability at Scale: Eliminating Blind Spots Across On-Premises, Cloud, and Hybrid Network Infrastructure

Unified DNS, DHCP IPAM Observability

Executive Summary

A Fortune 500 food manufacturer running Infoblox Universal DNS, DHCP, and IPAM (DDI) across three continents managed thousands of DNS records, DHCP leases, and IP allocations for tens of thousands of endpoints, but its telemetry lived in disconnected systems. Audit events, DNS query data, and IPAM records never correlated, so security incidents took hours to trace, subnets silently exhausted, and a single disabled DNS record went unnoticed until a business-critical application stopped resolving the following morning.

This case study shows how Crest Data’s Infoblox Universal DDI integration for Datadog turned that fragmented, reactive environment into a unified, correlated, proactive network observability platform, cutting investigation time from hours to minutes and identifying infrastructure failures before they reached end users.

About the Customer  

The customer is a globally recognized food and beverage manufacturer operating across North America, Europe, and Southeast Asia, with over 40 manufacturing facilities, cold-chain distribution centers, and hybrid cloud workloads. Its DNS, DHCP, and IPAM environment manages resolution, address assignment, and IP management for approximately 80,000 endpoints across on-premises Infoblox NIOS data centers, Azure-hosted workloads governed by Infoblox Universal DDI, and a growing edge compute footprint at manufacturing sites. A network engineering team maintains DNS, DHCP, and IPAM health across all regions, while a lean security operations center (SOC) handles threat monitoring, compliance auditing, and incident response.

Customer Challenge  

Growth compounded complexity faster than the existing tooling could absorb.

  • No unified view across on-premises and cloud. The two environments produced separate telemetry with no shared observability layer, so a single hybrid connectivity issue required parallel investigations in completely separate systems: no single pane of glass, no shared timeline, no common attribute structure.

  • Visibility fragmented across silos. DNS query logs, DHCP lease activity, IPAM records, audit events, and host and service health lived in separate systems. Diagnosing one connectivity report meant manually cross-referencing three or four consoles, a process that routinely stretched from minutes to two or three hours.

  • Subnet exhaustion was invisible until too late. With no proactive utilization alerting, subnets silently filled at three manufacturing sites over eighteen months; the first signal each time was a flood of helpdesk tickets, not a network alert, by which point production-floor operations were already affected.

  • Audit and change tracking was reactive. Building a compliant audit trail meant manually pulling Infoblox logs, cross-referencing Active Directory, and stitching a timeline in a spreadsheet. One quietly disabled DNS record took over fourteen hours to identify as the root cause of an application outage.

  • Security threats hid in DNS traffic. With no consolidated view of DNS query behavior, suspicious patterns, high NXDOMAIN rates, and unusual ANY query usage were caught only by chance, leaving the SOC without early warning of tunneling attempts or botnet activity.

  • Alert fatigue from generic monitoring. Generic infrastructure checks reported server availability and basic metrics, but nothing tied to actual DNS, DHCP, and IPAM service behavior, so real threats and misconfigurations went undetected.

Proposed Solution

Crest Data designed and deployed its Infoblox Universal DDI integration for Datadog, ingesting six data sources- audit logs, DNS records, DHCP lease activity, IPAM events, service logs, and host and service details- from both the on-premises and cloud infrastructure into a single Datadog workspace shared by network engineering and the SOC.

A shared log processing pipeline normalizes all six sources to Datadog’s standard attributes, creating one common vocabulary across every event type. When network.client.ip means the same thing in a DNS query log as in a DHCP lease record, and usr.name is populated consistently across audit events and DNS record modifications, cross-source correlation becomes a filter operation rather than a manual investigation.

Nine pre-built dashboards, each filterable by DNS server, region, subnet, IP space, host, and service type, plus twenty pre-configured monitors with real-world thresholds gave both teams purpose-built views and automated early warning across the failure and threat patterns that had historically slipped through.

DHCP Abuse, Lease Exhaustion, and Subnet Health

DHCP dashboards unify lease events, active client counts, and per-subnet activity, while six monitors flag abuse patterns and lease-deletion storms. Most valuable, “High Subnet Utilization” now warns before a subnet exhausts the gap that had silently taken sites offline for two years.

IPAM Reconciliation and IP Conflict Detection

The IPAM Events dashboard tracks address changes and lease-to-address reconciliation, enriched with device, vendor, and OS context, and three monitors catch the double-allocations and duplicate IPs across spaces that manual audits routinely missed.

Host and Service Health Across a Distributed Environment

A single dashboard unifies host and service error states, maintenance events, and change trends across all forty-plus sites, and “Host in Error State” and “Service in Error State” monitors fire on detection, before failures cascade to dependent services.

DNS Threat Detection and SOC Visibility

SOC Insights and DNS Query Logs dashboards expose query volume, NXDOMAIN rates, and source-IP rankings, with five monitors covering tunneling, botnet, and amplification patterns. Within sixty days, the SOC caught and isolated a DNS tunneling attempt from a manufacturing site in Malaysia.

DNS Record Change Audit and Security Accountability

Dashboards provide a searchable trail of every DNS record change by user, action, and zone, with monitors for disabled records and TXT modifications, closing the gap behind the disabled record that once caused a fourteen-hour outage.

Configuration Audit and Governance

The Audit Logs dashboard captures every configuration operation with user and geographic context and correlates it with DNS, DHCP, and IPAM activity from the same window, so events like “API Key Disabled” arrive fully enriched and authorization can be assessed without a separate console.

Outcomes & Success Metrics

  • Unified observability across on-premises and cloud. Network engineering and the SOC share a single environment covering both, resolving hybrid connectivity issues without data reshaping, tool switching, or context loss.
  • Investigation time reduced from hours to minutes. Cross-source correlation that once required querying four separate systems is now a filter operation within a single Datadog environment.
  • Complete audit accountability. Compliance preparation, once a multi-day manual effort, can now be achieved in minutes with a single query.

About Crest Data

Crest Data is an Advanced Datadog partner that helps enterprises migrate, integrate, and scale observability and security platforms. The Infoblox Universal DDI integration delivers complete DNS, DHCP, and IPAM observability aligned to real-world failure and threat patterns that teams face every day. It is available in the Datadog Marketplace and includes a 14-day free trial.