Good evening. We have been noticing strange DNS reverse lookups coming from our Solarwinds server. For example, it periodically looks up PTR 223.87.213.173.in-addr.arpa and receives a failure. We were made aware of a known issue when using LEM/Security Event Manager (see link below), but we do not have that component.
https://support.solarwinds.com/SuccessCenter/s/article/LEM-Looks-up-a-DNS-Record-from-a-Known-Problem-Site?language=en_US
Have you all seen similar activity? Could it somehow be Netpath/Netflow trying to resolve IPs? Thanks.