How to distinguish source IP vs destination IP in secure access events?
s42bm last edited by
<134>Juniper: 2016-01-23 01:18:47 - TSCMAGT01 - [[b]18.104.22.168] ……66Z&charset=ISO-8859-1&charset=ISO-8859-1 from 10.100.110.101 result=200 sent=151 received=327 in 0 seconds
<142>Juniper: 2015-05-21 13:32:07 - SSL-DCA-IA2 - [[b]172.17.19.28] steveno……2_NGAHR_DCI_MON_SYS, 2_ADMIN_H] - Network Connect: Session started for user with IP 172.24.2.126, hostname ……
I have two sample events here, does Juniper have regulations or conventions to distinguish source vs destination IPs in the events, such as Ip in  always the source? Help is appreciated.