Splunk Search

Source Workstation shows random IP

brosariochan
New Member

Hi there, I'm looking into why one of our users is getting locked out, but when I run a search to try to find out the source of the lockout, all I find is...

Source Workstation: IP-10-1-30-15

as the only possible identification of the source. This would show up multiple times per hour in roughly 10 minute intervals, and each time it'll change the last number of the series. I've tried to ping the Source Workstation but had it time out. Any help or insight would be great!

Tags (2)
0 Karma

DalJeanis
Legend

If those dashes are in the source exactly as presented, this is a really interesting thing. If they are not being spoofed, then the workstation (or other object) is behind some other kind of object that is assigning them an IP that changes every time, but also formats them oddly.

The 10.x.x.x IP addresses are private/local network addresses. One interpretation is that there is a workstation (or other object) out there periodically connecting to the network and your router (or other NAT hardware) is assigning that workstation (or other object) a new local network address whenever that workstation (or other object) periodically connects to the network.

You would have to ping the object immediately as soon as it connects, to communicate to it.

0 Karma

Richfez
SplunkTrust
SplunkTrust

Could you provide a little more information?

Where do you see the "IP-10-1-30-15"? Is it in a windows event code? Have you looked up the event code in Microsoft's docs (or eventid.net or wherever?) What else is in those events? Where are they being generated from?

I have seen this before, but I'm not sure exactly where. It was either a SAMBA server triggering an event on a real domain when it ... did something wrong with how it tries to log in? Or might have been a really old client that wasn't actually supported, like win98 or something.

So, more information would be helpful!

Happy Splunking,
Rich

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...