I have the following log and I am confused by the "direction=" portion. The following log shows "direction=outgoing", which would mean in return flow traffic, the the original dstIP is now sending out an infected file, is that right, or is the "direction=" based on the source IP? Log below is truncated.
type=utm subtype=virus eventtype=infected level=warning vd=\"root\" msg=\"File is infected.\" action=blocked service=SMTP sessionid=301025798 srcip=201.x.x.x dstip=192.168.x.x srcport=46776 dstport=25 srcintf=\"port1\" dstintf=\"Secure-305\" policyid=144 proto=6 direction=outgoing filename=\"BLE753615-03.doc\" quarskip=File-was-not-quarantined. virus=\"VBA/Agent.LMY!tr.dldr\" dtype=\"Virus\" ref=\"http://www.fortinet.com/v...%2FAgent.LMY%21tr.dldr\" virusid=7951454 profile=\"default
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1112 | |
759 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.