Can I get a couple users of either the "Snare for Windows Event Collector" or the "Microsoft Vista and Microsoft Windows Server 2008 Event Collector" to confirm something for me? After a full day of working in the office, could you to run the query below on your own userid and tell me if you have any events that day with your actual workstation's IP address in the IP Source Address field (or any of the normalized fields for that matter). All I see is the actual server IP addresses in this field. Obviously you will need to change the product to the correct Windows collector and enter your username.
(Mechanisms contains Login ANDProduct = Snare for Windows Event Collector AND (Windows User Name contains <enter your username> ORUser Name contains <enter your username>))