In a matter of 1 day I get well over 6000+ entries all of them being as follows
Application: Windows Operating System
Source IP: 169.254.1.251
Source Port: 0
Destination IP: 255.255.255.255
Destination Port: 0
This is not only the most annoying thing ever but it makes figuring out if I have real intrusions near impossible if someone could figure this out I would be very appreciative.
I would like to add that I have DHCP disabled I prefer to have a static IP and NETBIOS over tcpip is enabled as default.
Do you have another computer on you local network?
Yes, almost a dozen other items are on the same network.
When a computer cannot see a DHCP server to get an IP address it from Windows will provide an IP address in the 169 range. That means that one of the computers on your network does not have a fixed IP address set but is trying to get an IP address from a DHCP server (which is not there). It means either that one of computers is not correctly configured or there is a rogue computer on your network.
The firewall logs have an Advanced Filter option that may be helpful to filter out the traffic coming from the specific IP address.