@cwgcad As George said this looks like a response packet. With source port 80 this must be the case I would think. So please figure out what the other IP is!

Matching the alerts with httpd log in the FOG server is a great idea.