@PhoneBoy , If you look closely at the log shown, you'll see that it only shows date, not time of the incident. We have only option to "View Host Logs" from the "Infected Hosts" section.
This opens up logs filtered by the host's IP with the current date and time.
The SMB appliances log query does not permit multiple filters, but only one:
So we have to either scroll back to the date and look at ALL THE LOGS for that host or filter by the host and look for ALL THE LOGS for that date.
What do you think the likelihood of finding what we are looking for?