Splunk Search

Source Workstation shows random IP

brosariochan
New Member

Hi there, I'm looking into why one of our users is getting locked out, but when I run a search to try to find out the source of the lockout, all I find is...

Source Workstation: IP-10-1-30-15

as the only possible identification of the source. This would show up multiple times per hour in roughly 10 minute intervals, and each time it'll change the last number of the series. I've tried to ping the Source Workstation but had it time out. Any help or insight would be great!

Tags (2)
0 Karma

DalJeanis
Legend

If those dashes are in the source exactly as presented, this is a really interesting thing. If they are not being spoofed, then the workstation (or other object) is behind some other kind of object that is assigning them an IP that changes every time, but also formats them oddly.

The 10.x.x.x IP addresses are private/local network addresses. One interpretation is that there is a workstation (or other object) out there periodically connecting to the network and your router (or other NAT hardware) is assigning that workstation (or other object) a new local network address whenever that workstation (or other object) periodically connects to the network.

You would have to ping the object immediately as soon as it connects, to communicate to it.

0 Karma

Richfez
SplunkTrust
SplunkTrust

Could you provide a little more information?

Where do you see the "IP-10-1-30-15"? Is it in a windows event code? Have you looked up the event code in Microsoft's docs (or eventid.net or wherever?) What else is in those events? Where are they being generated from?

I have seen this before, but I'm not sure exactly where. It was either a SAMBA server triggering an event on a real domain when it ... did something wrong with how it tries to log in? Or might have been a really old client that wasn't actually supported, like win98 or something.

So, more information would be helpful!

Happy Splunking,
Rich

0 Karma
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...

Buttercup Games: Further Dashboarding Techniques (Part 5)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Customers Increasingly Choose Splunk for Observability

For the second year in a row, Splunk was recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for ...