On a RasPi, I run PiHole to see what is happening in/on my network.
The other day I am noticing HUGE traffic to the name heartbeat
.
(Bit of a give away to me, but indulge me)
I have since discovered my backups failed and so I have none. Only the working flow/s.
(That has since been fixed)
Ok, I have a back up but from March...... This year.
So the problem that I am seeing:
This is what PiHole is showing me in a very filtered log:
Jun 17 19:32:27 dnsmasq[9674]: query[A] heartbeat from 192.168.0.99
Jun 17 19:32:27 dnsmasq[9674]: config heartbeat is NXDOMAIN
Jun 17 19:32:27 dnsmasq[9674]: query[A] heartbeat from 192.168.0.99
Jun 17 19:32:27 dnsmasq[9674]: config heartbeat is NXDOMAIN
Jun 17 19:32:28 dnsmasq[9674]: query[A] heartbeat from 192.168.0.99
Jun 17 19:32:28 dnsmasq[9674]: config heartbeat is NXDOMAIN
Jun 17 19:32:28 dnsmasq[9674]: query[A] heartbeat from 192.168.0.99
Jun 17 19:32:28 dnsmasq[9674]: config heartbeat is NXDOMAIN
Started 19:32 17 June. Local time I hope.
But what ever.... From then it has been relentless.
What I've done to try and find it:
Every 30 seconds I send out nmap
commands with IP ranges of my LAN and my uplink.
(Other post)
That is old now.
But that happens every 30 seconds.
I look at the log of PiHole and it is continuing to be logged.
I disable that part of the flow. Alas it continues.
Ok, not the end of the world.
But to be sure - rather than going through all the tabs - I stopped NR.
The entries stopped. (Phew)
Yes, ok, I could step through them all and disable them and find out when it starts again.
But it is confusing to me.
I'm guessing I am pinging
and for some reason heartbeat
is being given rather than an IP address.
I get that.
But I haven't got any ping
nodes used now.
They've been superseded with nmap
commands.
Any thoughts on how to track it down?
(Maybe I disable 1/2 the tabs. If it remains, disable another 1/2 of the active tabs.
If it is good, enable 1/2 of the tabs and see what happens.)
Sorry folks. I am really having a few bad days just now.