I would like to believe it's not an attack except it's happening to about six servers and the requests are malformed. It's sending things like three or four character URLs IE: sftm or cme without http:// or ftp://, etc. I suppose it could be a rogue cache server

Stuart