CHAPTER 29
FLOW System Log Messages
This chapter describes messages with the FLOW prefix. They are generated by the process
that handles flows on routers running the Junos OS with enhanced services.
FLOW_HIGH_WATERMARK_TRIGGERED
System Log Message Number of sessions current-flows exceeded the high watermark limit. Early aging triggered.
Description Early aging of sessions is triggered when the number of concurrent session entries in the
session table exceeds the configured high watermark. When the number of concurrent
sessions drops below the configured low watermark, the router stops aggressively aging
out sessions. This message notifies you that the session high watermark has been
exceeded and aggressive aging of sessions has begun.
Type Event: This message reports an event, not an error
Severity info
Facility LOG_PFE
FLOW_IP_ACTION
System Log Message Flow IP action detected attack attempt: source-address/source-port -->
destination-address/destination-port from interface interface-name, from zone
source-zone-name, action action.
Description Flow IP action notification is generated when a new connection matches security flow
IP action filter that has been setup to log or has ip-notify action
Type Event: This message reports an event, not an error
Severity info
Facility LOG_PFE
FLOW_LOW_WATERMARK_TRIGGERED
System Log Message Number of sessions current-flows dropped below the low watermark limit. Early aging
stopped.
Description Early aging of sessions is triggered when the number of concurrent session entries in the
session table exceeds the configured high watermark. When the number of concurrent
sessions drops below the configured low watermark, the router stops aggressively aging
267Copyright © 2010, Juniper Networks, Inc.