Splunk Search

Source Workstation shows random IP

brosariochan
New Member

Hi there, I'm looking into why one of our users is getting locked out, but when I run a search to try to find out the source of the lockout, all I find is...

Source Workstation: IP-10-1-30-15

as the only possible identification of the source. This would show up multiple times per hour in roughly 10 minute intervals, and each time it'll change the last number of the series. I've tried to ping the Source Workstation but had it time out. Any help or insight would be great!

Tags (2)
0 Karma

DalJeanis
Legend

If those dashes are in the source exactly as presented, this is a really interesting thing. If they are not being spoofed, then the workstation (or other object) is behind some other kind of object that is assigning them an IP that changes every time, but also formats them oddly.

The 10.x.x.x IP addresses are private/local network addresses. One interpretation is that there is a workstation (or other object) out there periodically connecting to the network and your router (or other NAT hardware) is assigning that workstation (or other object) a new local network address whenever that workstation (or other object) periodically connects to the network.

You would have to ping the object immediately as soon as it connects, to communicate to it.

0 Karma

Richfez
SplunkTrust
SplunkTrust

Could you provide a little more information?

Where do you see the "IP-10-1-30-15"? Is it in a windows event code? Have you looked up the event code in Microsoft's docs (or eventid.net or wherever?) What else is in those events? Where are they being generated from?

I have seen this before, but I'm not sure exactly where. It was either a SAMBA server triggering an event on a real domain when it ... did something wrong with how it tries to log in? Or might have been a really old client that wasn't actually supported, like win98 or something.

So, more information would be helpful!

Happy Splunking,
Rich

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...