In case ES-608-189, a retail SOC runs ES 7.2 with Security Content Update enabled. During an IP indicator matches internal vulnerability scanner traffic, the team sees inconsistent results across notables, dashboards, or investigation pivots. Two unrelated Windows forwarders were also patched that morning. Which response should the ES administrator take first?