Thank you, choly
I checked our top Endpoints page again, looking for ingress hosts and found that the "." host was still present. Opening up the plus button led to several devices, and it was apparent which interface the majority of the traffic was coming through (compared against the Ingress Bytes or Ingress Packets field). After that, checking the interface brought up the ip address.
It seems this can also show multiple hosts, so we'll have to play around with this until we can clearly identify which host is the source of the traffic.