is FortiGate's way of saying the address is private, so there is no country to report. Records like this are the bulk of firewall logging: a single busy firewall produces hundreds of thousands a day, and no one ever reads an individual one." /> is FortiGate's way of saying the address is private, so there is no country to report. Records like this are the bulk of firewall logging: a single busy firewall produces hundreds of thousands a day, and no one ever reads an individual one." />

What this Log Means?

Log: fortigate-traffic-close
date=2026-08-11 time=02:59:59 devname="FORTI-FW-FGT" devid="FGVMEV0000000000" eventtime=1786406399301548690 tz="+0300" logid="0000000013" type="traffic" subtype="forward" level="notice" vd="root" srcip=10.22.2.4 srcport=60799 srcintf="port2" dstip=18.157.69.54 dstport=443 dstintf="port1" srccountry="Reserved" dstcountry="Germany" sessionid=65243676 proto=6 action="close" policyid=1 policyname="LAN-OUT" service="HTTPS" duration=2 sentbyte=1663 rcvdbyte=6019 sentpkt=15 rcvdpkt=14
For: Fortinet FortiGate firewall (traffic)

Meaning: A session ended normally. action=close means the connection completed and was torn down, not that anything was blocked. An internal machine (10.22.2.4) reached a server in Germany over HTTPS, sent 1,663 bytes and received 6,019 over 2 seconds, under the policy named LAN-OUT.

srccountry="Reserved" is FortiGate's way of saying the address is private, so there is no country to report. Records like this are the bulk of firewall logging: a single busy firewall produces hundreds of thousands a day, and no one ever reads an individual one.

What to do: None. The value of these is in aggregate, not individually: which networks your users reach, how much data moves, and when that pattern changes. Trunc counts them and shows the shape without storing every line, so they cost you nothing.
< back for more logs

Simple, Affordable, Log Management and Analysis.

14 days free trial. No credit card required.