Technical Tip: UDP-based sessions exhibit a discrepancy of 3 minutes between the timestamps in the forward traffic logs and the security event logs
Description | This article describes why a 3-minute timestamp discrepancy between the Forward Traffic and Security Event logs is expected for UDP-based sessions that are blocked by a UTM profile. |
Scope | FortiGate. |
Solution | The default idle timer for a UDP session in FortiGate is 180 seconds (3 minutes), and it is a configurable parameter in the global settings:
![]()
![]()
|


