Question
IPS logs with Attack ID 0 and Attack Name Unknown?
I'm seeing some IPS logs for outbound connections that show no ID or name, like so:
Attack Name Unknown Attack ID 0 Reference https://fortiguard.com/encyclopedia/ips/0
Message : ,
Event Type signature
Protocol Number 6
Type utm
Sub Type ips
Destination
IP 52.162.166.27 Host Name client-s.gateway.messenger.live.com Port 443 Destination Interface Hostname ch1-client-s.gateway.messenger.live.com URL ch1-client-s.gateway.messenger.live.com Application Protocol tcp Service P2P
Action detected
Any ideas what might be going on?
