You can enable logging on the firewall rule that passes traffic for that.

If it's passed by a catch-all rule you can add a more specific pass rule above that to catch only that.

Steve