What Azure storage service has the User-Agent tag of 'services_xstore_transport_HTTP2/1.0'

Kif F 0 Reputation points
2025-12-12T00:23:20.7233333+00:00

Does anyone know what service is generating these logs on a GRS storage account? I'm assuming this is Azure backend replication, but these events only started happening less than 48 hours ago.

I've been looking at logs and this has been alerting due to coming from an unknown private IP address, based on key authentication, accessing what should be a restricted file share.

Below is the KQL query on the storage account logs

StorageFileLogs
| order by TimeGenerated desc
| where CallerIpAddress !contains "<Internal CIDR>"
| where AuthenticationHash !contains 'system-1'
| project TimeGenerated, AuthenticationType, StatusCode, CallerIpAddress, UserAgentHeader

These are the results, across a range of IPs. This screenshot shows 100.75.x.y, but there have also been 10.x.y.z IP addresses which don't belong to our internal network environment (either in Azure or otherwise).

Screenshot 2025-12-12 111805

Azure Storage
Azure Storage
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.