SUMMARY: mysterious IP in syslog

From: Christopher Barnard <cbarnar1_at_earthlink.net>
Date: Sat Jul 17 2010 - 13:07:55 EDT
I asked

> We have a central syslog server in our environment.  Since every line in
> a syslog entry includes the server name, we are able to determine which
> server sent the alert.  However, we have one server that instead of a
> hostname has a six-octet number.  This doesn't happen often, and most of
> the time it is not anything bad (like this one), but when it does it is
> baffling because we do not know where it is coming from...
>
> Jul 13 22:05:32 [10.74.131.27.169.106] sshd[20280]: [ID 800047
> auth.info] Accepted publickey for epicadm from 10.74.4.20 port 35428
> ssh2
>
> 10.74. is definitely recognizable as an IP range we use.  10.74.131. is not
> however.
>
> The user 'epicadm' is not very descriptive because this is a group account
> (yes, I know.  group account = evil) and that group account exists on
almost
> every server.
>
> Any ideas how to track down the mysterious 10.74.131.27.169.106?

The answer:

Ah, the continuing clash between network administrators and system
administrators.  Thanks to the individual who pointed me to Cisco's FAQ page.
This is an issue that sysadmins bring up regularly and network admins have to
explain regularly.  All of the gory details are at

https://supportforums.cisco.com/thread/168873?tstart=0

Thanks to:

Taylor, Matthew <Matthew.Taylor@montgomerycollege.edu>
Harka Gyozo <carlos@gamma.ttk.pte.hu>
Charles Morris <cmorris@cs.odu.edu>
Ric Anderson <ric@Opus1.COM>
Bill Voight <bvoight@patriot.net>
John.Hallman@wellsfargo.com
joel.britt.ctr@jfcom.mil


Christopher L. Barnard
-------------------
comment your code as if the maintainer is a homicidal maniac who knows where
you live.
_______________________________________________
sunmanagers mailing list
sunmanagers@sunmanagers.org
http://www.sunmanagers.org/mailman/listinfo/sunmanagers
Received on Sat Jul 17 13:09:22 2010

This archive was generated by hypermail 2.1.8 : Thu Mar 03 2016 - 06:44:17 EST