Hi,
WE have recently been experiencing a huge number of PCs that are regularly changing their domain name from the NETBIOS name to the Active Directory FQDN name and then back again in LanSweeper, with comments like
21/11/2019 20:45 Renamed DOMAIN.org.tld\wdbah28573.DOMAIN.org.tld\1 to DOMAIN\WDBAH28573\1
21/11/2019 17:23 Renamed DOMAIN\WDBAH28573\1 to DOMAIN.org.tld\wdbah28573.DOMAIN.org.tld\1
21/11/2019 16:45 Renamed DOMAIN.org.tld\wdbah28573.DOMAIN.org.tld\1 to DOMAIN\WDBAH28573\1
21/11/2019 14:22 Renamed DOMAIN\WDBAH28573\1 to DOMAIN.org.tld\wdbah28573.DOMAIN.org.tld\1
21/11/2019 12:44 Renamed DOMAIN.org.tld\wdbah28573.DOMAIN.org.tld\1 to DOMAIN\WDBAH28573\1
21/11/2019 11:06 Renamed DOMAIN\WDBAH28573\1 to DOMAIN.org.tld\wdbah28573.DOMAIN.org.tld\1
21/11/2019 08:44 Renamed DOMAIN.org.tld\wdbah28573.DOMAIN.org.tld\1 to DOMAIN\WDBAH28573\1
21/11/2019 05:06 Renamed DOMAIN\WDBAH28573\1 to DOMAIN.org.tld\wdbah28573.DOMAIN.org.tld\1
21/11/2019 04:44 Renamed DOMAIN.org.tld\wdbah28573.DOMAIN.org.tld\1 to DOMAIN\WDBAH28573\1
21/11/2019 02:06 Renamed DOMAIN\WDBAH28573\1 to DOMAIN.org.tld\wdbah28573.DOMAIN.org.tld\1
The changes from NETBIOS to FQDN seem to be associated with the time of the last Last IP Range Scan, but I cant be sure.
The change from FQDN to NETBIOS seem to be associated with an active scan or a power-on
We switch off most PCs overnight for power saving, so early in the morning as PCs get switched on there are maybe 50 PCs in the FQDN domain, but by the evening there could be a thousand.
The swap temporarily creates a "new" record becasue of the different name. Becasue the NETBIOS and FQDN PCs end up getting merged, the "first seen" date is getting messed up. PCs that are on the network for years are showing a "first seen" date of only a couple of days ago, becasue if the old record gets merged into the new one, the first seen date is taken from the new record
Any ideas to resolve or investigate the root cause would be appreciated