Looking at my syslog traffic, I noticed the field "fwrule" with some number i.e 60006. I also see an "ID" field. This field has number like 2002, 2000, 2102...Which is the FW rule the traffic triggered (So I can look up the rule in the firewall) and which is the IPS rule (If it is anyone of those two) Lastly, is there a list of IPS rule IDs to look at?
Thanks.
This thread was automatically locked due to age.