I have UFW block messages from local network machines, how can I analyse if they are malicious?
- by Trygve
I'm getting a lot of messages in my UFW log, and I'm trying to figure out if these are malicious or just normal. A UDP broadcast is coming from a windows laptop x.x.x.191, and some from our synology disks x.x.x.{6,8,10,11}. I have not figured out which macine 114 is yet.
I would appreciate some advice in how to read the log, and get the most I can…