Good morning, all!

I'm just wondering about something I'm seeing in my Analyzer reports. There are often two entries on the report for the same host - one with just the IP address and one with both the address and the FQDN. These entries with just the IP address are often referring to hosts in our domain that have DNS entries.

My first idea is that the difference comes from some traffic referring to the FQDN, or just the hostname, and some referring only to the IP address. It does seem a bit strange that Analyzer can't or won't summarize the two.

Does anyone have some insight into this behavior in Analyzer?

Thanks in advance to all!