Skip to main content
rmehta
Staff
Staff
February 27, 2026

Technical Tip: Blank result field in forward traffic logs

  • February 27, 2026
  • 0 replies
  • 400 views
Description This article describes why the result field in forward traffic logs may appear blank.
Scope FortiGate.
Solution

The result field is populated when the log entry does not have a specific action or outcome recorded for that session. 

 Untitled picture.png

 

If all of the following criteria are met, the result field remains blank. This behavior indicates normal session completion.

  • Is allowed by a firewall policy: If the session is allowed by the firewall policy without any issues.
  • Has UTM Inspection: The session passes through UTM inspection without any blocks, warnings or alerts.
  • Has a normal session closure: The session closes normally without any errors or specific termination reasons.

 

The result field is populated in scenarios where there is a termination reason or security action, such as:

  • Deny: The session is blocked by a policy.
  • Timeout: The session times out due to inactivity.
  • Client-RST / Server-RST: The session is reset by the client or server.
  • Blocked: The session is blocked due to a UTM action.
  • Detected: An event is detected by an antivirus or IPS (Intrusion Prevention System).

If none of these events occur, the result field will not be populated.