Across 20 Pix's, over 50% of my syslog messages are inbound on SOURCE port 80 (message 106023) from the internet to our PAT address. It doesn't seem to have any effect on our traffic but it is basically giving us way to many false positives on the syslog server.
I know there is a way to remove a syslog message completely, but can it be pruned based on other criteria (such as source port)?
Thanks
Paul