Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
cmac72879
New Contributor

question regarding the "direction=" in logs

I have the following log and I am confused by the "direction=" portion. The following log shows "direction=outgoing", which would mean in return flow traffic, the the original dstIP is now sending out an infected file, is that right, or is the "direction=" based on the source IP? Log below is truncated.

 

type=utm subtype=virus eventtype=infected level=warning vd=\"root\" msg=\"File is infected.\" action=blocked service=SMTP sessionid=301025798 srcip=201.x.x.x dstip=192.168.x.x srcport=46776 dstport=25 srcintf=\"port1\" dstintf=\"Secure-305\" policyid=144 proto=6 direction=outgoing filename=\"BLE753615-03.doc\" quarskip=File-was-not-quarantined. virus=\"VBA/Agent.LMY!tr.dldr\" dtype=\"Virus\" ref=\"http://www.fortinet.com/v...%2FAgent.LMY%21tr.dldr\" virusid=7951454 profile=\"default

0 REPLIES 0
Labels
Top Kudoed Authors