The way I usually try to find a problem device is by segmenting the network. I have used this to find bad switches, bad NICs, and a rouge dhcp. I will usually setup something like a continuous ping, wireshark or dhcpfind by roadkill. then I start at the fiber and disconnect a building at a time till i know which building. Then I go to that building and disconnect a switch at a time till I find which switch then unplug each jack until I know which jack the device is plugged into, look up the location of that jack and go get the device. The downside of this technique is you are disconnecting a lot of users. The upside is you will have the device in you hand in about 5 minutes, and you didn't need to use any fancy software or hardware.