Your firewall blocked the attack. So why should you still investigate it?
A firewall blocks a connection from an unfamiliar IP address. The event appears in the log, the traffic never reaches the intended service, and the security control has done exactly what it was supposed to do. At first glance, there seems to be little reason to investigate further.
That conclusion can be misleading.

A blocked connection tells you that one particular action was prevented. It does not necessarily tell you what happened before the block, whether the same source tried another route, whether other systems were targeted, or whether a different attempt eventually succeeded. In many cases, the firewall event is not the incident itself. It is only one visible part of a wider sequence.
This is why blocked firewall events can still be valuable security information. The important question is not simply whether the firewall stopped the traffic, but what the blocked activity means in the context of everything else happening around it.



