Resolved! PanOS 10.1.14-h2 - How does Palo identify if traffic belongs to an 'ms-update' application flow
I need to understand exactly makes a TCP flow identified as the 'ms-update' application.
I found the Objects -> Applications -> ms-update app description. It shows the ports used, and other dependencies. But this does not explain exactly what makes