Hi mates,
We are monitoring a fortigate unit, and this device is sending logs to our SIEM.
There is a particular thing, when we check a top 10 services based on logs: we can see that many of these logs brings the description as "VideoMSN" but, the ports involved in sessions are TCP 25, 22, and so on...
I mean, these ports are well known ports for specific services, but I cannot figure out why logs are showing this "VideoMSN" description. There are other logs that shows the service according to the port involved, for example "SMTP" for port 25.
I would appreciate if someone can give me a hint about this behavior.
Regards,
User | Count |
---|---|
2249 | |
1222 | |
771 | |
451 | |
366 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.