Our Network department alerted me that our enVision appliance was sending out a large stream of UDP-137 NetBIOS Name Query (NBSTAT) requests to external/public IP addresses. When I verified this on the appliance using a packet capture, I can't match the destination IP addresses with anything related to log data enVision is processing (i.e. enVision attempting to resolve the name of the destination IP address).
We're seeing around 2,000 of these packets every minute.
Is anyone seeing the same on their appliance?