cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
298
Views
11
Helpful
3
Replies

CS-Mars Query ?

thornick
Level 1
Level 1

Running vs. 4.1 ... When I run a query on a specific clients source IP address, I am getting alot of Destination IP of 0.0.0.0 .... is this normal? Is there something I am missing in configuration?

3 Replies 3

a.kiprawih
Level 7
Level 7

Hi,

It's normal, as it was generated by the device itself. This is why you see the 0.0.0.0 can either be a source or destination IP.

Same goes to interface up/down for a device where if the device itself is sending log to MARS, you'll see the same 0.0.0.0 appear.

Rgds,

AK

JUCETA
Level 1
Level 1

Hi,

It's normal. I guess you're getting information from logon events (authentication failure, Windows 2000 login sucessful, etc) That's because there're some event logs without IP information and traffic used is not IP routed (NetBIOS, p.e.) In this manner, if you look at the raw message you'll see the logon information (username, password, domain controller like reporting device, etc)

It's normal.

Good luck!

Thank you!