The "bad"
Jan 25 13:29:36 fw_bad RT_FLOW AppTrack session created 192.168.1.31/58828->192.168.2.150/161 None SNMP-VERSION-2U UNKNOWN 192.168.1.31/58828->192.168.2.150/161 N/A N/A 17 vpn-2-trust VPN trust 15249 N/A N/A No
Jan 25 13:29:37 fw_bad RT_FLOW AppTrack session created 192.168.2.88/54257->10.16.20.223/3283 None UNKNOWN UNKNOWN WAN/14826->10.16.20.223/3283 source-nat-rule N/A 6 trust-to-untrust trust untrust 12495 N/A N/A UNKNOWN
Jan 25 13:29:37 fw_bad RT_FLOW session created 192.168.2.88/54257->10.16.20.223/3283 None WAN/14826->10.16.20.223/3283 source rule source-nat-rule N/A N/A 6 trust-to-untrust trust untrust 12495 N/A(N/A) vlan.0 UNKNOWN UNKNOWN UNKNOWN
Jan 25 13:29:37 fw_bad RT_FLOW session closed idle Timeout: 192.168.2.88/54256->10.16.20.30/3283 None WAN/11012->10.16.20.30/3283 source rule source-nat-rule N/A N/A 6 trust-
Jan 25 13:29:37 fw_bad RT_FLOW AppTrack session closed idle Timeout: 192.168.2.88/54256->10.16.20.30/3283 None UNKNOWN UNKNOWN WAN/11012->10.16.20.30/3283 source-nat-rule N/A 6 trust-to-untrust trust untrust 12831 2(96) 0(0) 20 N/A N/A No
Jan 25 13:29:37 fw_bad RT_FLOW session closed idle Timeout: 192.168.2.88/54255->10.16.20.223/3283 None WAN/8361->10.16.20.223/3283 source rule source-nat-rule N/A N/A 6 trus
Jan 25 13:29:37 fw_bad RT_FLOW AppTrack session closed idle Timeout: 192.168.2.88/54255->10.16.20.223/3283 None UNKNOWN UNKNOWN WAN/8361->10.16.20.223/3283 source-nat-rule N/A 6 trust-to-untrust trust untrust 12996 2(96) 0(0) 20 N/A N/A No
Jan 25 13:29:37 fw_bad RT_FLOW session closed idle Timeout: 192.168.2.88/54254->10.16.20.218/3283 None WAN/19362->10.16.20.218/3283 source rule source-nat-rule N/A N/A 6 tr
Jan 25 13:29:37 fw_bad RT_FLOW AppTrack session closed idle Timeout: 192.168.2.88/54254->10.16.20.218/3283 None UNKNOWN UNKNOWN WAN/19362->10.16.20.218/3283 source-nat-rule N/A 6 trust-to-untrust trust untrust 11979 2(96) 0(0) 20 N/A N/A No
Jan 25 13:29:37 fw_bad RT_FLOW session closed idle Timeout: 192.168.2.88/54253->10.16.20.216/3283 None WAN/21005->10.16.20.216/3283 source rule source-nat-rule N/A N/A 6 tr
Jan 25 13:29:37 fw_bad RT_FLOW AppTrack session closed idle Timeout: 192.168.2.88/54253->10.16.20.216/3283 None UNKNOWN UNKNOWN WAN/21005->10.16.20.216/3283 source-nat-rule N/A 6 trust-to-untrust trust untrust 10231 2(96) 0(0) 20 N/A N/A No
Jan 25 13:29:37 fw_bad RT_FLOW session closed idle Timeout: 192.168.2.88/54252->10.16.20.204/3283 None WAN/3453->10.16.20.204/3283 source rule source-nat-rule N/A N/A 6 trus
Jan 25 13:29:37 fw_bad RT_FLOW AppTrack session closed idle Timeout: 192.168.2.88/54252->10.16.20.204/3283 None UNKNOWN UNKNOWN WAN/3453->10.16.20.204/3283 source-nat-rule N/A 6 trust-to-untrust trust untrust 13442 2(96) 0(0) 20 N/A N/A No
Jan 25 13:29:37 fw_bad RT_FLOW session closed idle Timeout: 192.168.2.88/54251->10.16.16.8/3283 None WAN/28501->10.16.16.8/3283 source rule source-nat-rule N/A N/A 6 trust-to-u
Jan 25 13:29:37 fw_bad RT_FLOW AppTrack session closed idle Timeout: 192.168.2.88/54251->10.16.16.8/3283 None UNKNOWN UNKNOWN WAN/28501->10.16.16.8/3283 source-nat-rule N/A 6 trust-to-untrust trust untrust 13008 2(96) 0(0) 20 N/A N/A No
Jan 25 13:29:37 fw_bad RT_FLOW session closed idle Timeout: 192.168.2.88/54250->10.16.20.221/3283 None WAN/25920->10.16.20.221/3283 source rule source-nat-rule N/A N/A 6 tr
Jan 25 13:29:37 fw_bad RT_FLOW AppTrack session closed idle Timeout: 192.168.2.88/54250->10.16.20.221/3283 None UNKNOWN UNKNOWN WAN/25920->10.16.20.221/3283 source-nat-rule N/A 6 trust-to-untrust trust untrust 12698 2(96) 0(0) 20 N/A N/A No
Jan 25 13:29:37 fw_bad RT_FLOW session closed idle Timeout: 192.168.2.88/54249->10.16.20.223/3283 None WAN/19279->10.16.20.223/3283 source rule source-nat-rule N/A N/A 6 tr
Jan 25 13:29:37 fw_bad RT_FLOW AppTrack session closed idle Timeout: 192.168.2.88/54249->10.16.20.223/3283 None UNKNOWN UNKNOWN WAN/19279->10.16.20.223/3283 source-nat-rule N/A 6 trust-to-untrust trust untrust 15037 2(96) 0(0) 20 N/A N/A No
Jan 25 13:29:38 fw_bad RT_FLOW AppTrack session created 192.168.1.31/44562->192.168.2.150/161 None SNMP-VERSION-2U UNKNOWN 192.168.1.31/44562->192.168.2.150/161 N/A N/A 17 vpn-2-trust VPN trust 10377 N/A N/A No
Jan 25 13:29:38 fw_bad RT_FLOW AppTrack session created 192.168.1.31/49502->192.168.2.150/161 None SNMP-VERSION-2U UNKNOWN 192.168.1.31/49502->192.168.2.150/161 N/A N/A 17 vpn-2-trust VPN trust 13366 N/A N/A No
The bad one
Jan 25 12:29:38 fw-good RT_FLOW: APPTRACK_SESSION_CREATE: AppTrack session created 192.168.1.31/40816->192.168.2.150/161 None SNMP UNKNOWN 192.168.1.31/40816->192.168.2.150/161 N/A N/A 17 trust-2-vpn trust VPN1 30602 N/A N/A No
Jan 25 12:29:45 fw-good RT_FLOW: APPTRACK_SESSION_CLOSE: AppTrack session closed idle Timeout: 192.168.1.31/0->192.168.2.250/7339 icmp ICMP ICMP-ECHO 192.168.1.31/0->192.168.2.250/7339 N/A N/A 1 trust-2-vpn trust VPN1 28421 1(84) 0(0) 60 N/A N/A No
Jan 25 12:29:45 fw-good RT_FLOW: APPTRACK_SESSION_CLOSE: AppTrack session closed idle Timeout: 192.168.1.31/0->192.168.2.250/7342 icmp ICMP ICMP-ECHO 192.168.1.31/0->192.168.2.250/7342 N/A N/A 1 trust-2-vpn trust VPN1 28811 1(84) 0(0) 59 N/A N/A No
Jan 25 12:29:45 fw-good RT_FLOW: APPTRACK_SESSION_CLOSE: AppTrack session closed idle Timeout: 192.168.1.31/0->192.168.2.250/7344 icmp ICMP ICMP-ECHO 192.168.1.31/0->192.168.2.250/7344 N/A N/A 1 trust-2-vpn trust VPN1 25380 1(84) 0(0) 59 N/A N/A No
Jan 25 12:29:49 fw-good RT_FLOW: APPTRACK_SESSION_CLOSE: AppTrack session closed idle Timeout: 192.168.1.31/51385->192.168.10.6/161 None SNMP UNKNOWN 192.168.1.31/51385->192.168.10.6/161 N/A N/A 17 trust-2-VPN2 trust VPN2 29081 1(89) 1(104) 59 N/A N/A No
Jan 25 12:29:49 fw-good RT_FLOW: APPTRACK_SESSION_CLOSE: AppTrack session closed idle Timeout: 192.168.1.31/54218->192.168.10.6/161 None SNMP UNKNOWN 192.168.1.31/54218->192.168.10.6/161 N/A N/A 17 trust-2-VPN2 trust VPN2 28731 1(77) 1(77) 59 N/A N/A No
Jan 25 12:29:49 fw-good RT_FLOW: APPTRACK_SESSION_CLOSE: AppTrack session closed idle Timeout: 192.168.1.31/59097->192.168.10.6/161 None SNMP UNKNOWN 192.168.1.31/59097->192.168.10.6/161 N/A N/A 17 trust-2-VPN2 trust VPN2 32150 1(82) 1(83) 59 N/A N/A No
Jan 25 12:29:49 fw-good RT_FLOW: APPTRACK_SESSION_CLOSE: AppTrack session closed idle Timeout: 192.168.1.31/39859->192.168.10.6/161 None SNMP UNKNOWN 192.168.1.31/39859->192.168.10.6/161 N/A N/A 17 trust-2-VPN2 trust VPN2 30290 1(82) 1(83) 59 N/A N/A No
the log messages are different for sure, some part is missing/different and this shifts all data, so make the log filtering system confusing