For non-URL Filtering logs, XFF IP logging is supported only when packet capture is not enabled. -->> It mean that XFF ip is visible only when packet capture is not enable in other logs setting ?---yes
The X-Forwarded-For IP column does not display a value if the firewall detects a threat that requires a reset action (reset-client, reset-server, or reset-both ) and the last inspected packet does not contain the XFF header.
-->> This mean as once firewall detects any threat with action "reset", the decoder will stop decoding further packet. If the XFF field does not reside in the last packet, we have no way to parse it. However if XFF field already reside in the last packet, then you are still able to see it. That's why for reset action there still might be a chance to see the value on the X-Forwarded-For IP column.
... View more