The short answer is "no". In general it is not possible for the receiving end to learn which process generated the traffic on the other side That fact is not advertised over the network.
Here's a suggestion:
1, Start and keep running a packet capture on the FortiGate (filter for hosts 192.168.0.16 + 192.168.0.1, and for your SSH port) -> This will tell you which source-port was used.
1.a, Alternatively, if you are logging local-in traffic, find these sessions in the Local Traffic log.
2, With this info, you might be able to trace which process generated this traffic on the Windows server end, assuming there's a way to log which processes used which source ports. (I don't know)
Another alternative: Perhaps you have some firewall application installed on the Windows server? If yes, check if you can set it up to block this traffic and log it. Then maybe this log will tell you which process tried to initiate that connection.
one addition: Since this is SSH, the initial communication is a "Protocol version exchange", which tends to include the version of the client/server. You can try looking at that in the packet capture, maybe that will give a hint as to which process is the client on the Windows server.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.