@ wilderness - I don't check headers on traffic. I did not go back to download the logs so I did not see the UA, not even sure which domain that came in from without further digging. When I get a notification of an IP in a trap I do a whois to get the CIDR to add to the master list and that one came from Microsoft. I don't do logs every day unless something startling needs attention. It will get matched up with a UA when I check logs.