Hello, I have recently had some doubts about some security logs in a 790 firewall, such as the following three examples:

Both the source and the destination are servers on the same network segment, for example The three events shown are sourced by the same server ( but at two destinations (, This leads me to think that the server has malware, but it has the Harmony Endpoint installed, I have verified and everything seems to be fine.
But the alerts keep coming constantly, what can I do in this case?
While on the other console of the 790, it tells me that it is infected.