Internal audit is performing searches on a sample set of network devices and noticed that we get different results (both record count and event types) when performing an nDepth search by IP address or by Name (within the IP address field). Can anyone explain why that is... The device is a virtual machine. By IP address we see events such as: MachineLogon, UserAuthTicket and InternalToolOnline. By Name we see many more (yet different) event types: PolicyModify, ServiceWarning, ServiceStop, ServiceStart, ObjectAudit, ServiceInfo, ProcessStop and InternalToolOnline.
Any assistance in understanding why this is would be greatly appreciated.