Hi@Arjunbrech,
Generally, the firewalls of USG6000 V100R001C10/V100R001C20/V100R001C30 output session logs once after 10 session logs are accumulated. If there is no session on the firewall during the accumulation, the firewall sends all the session logs accumulated before, regardless of the quantity.
You can run the reset firewall session table command to clear all session information. After the command execution, no session information exists on the firewall (including the root system and virtual system). The firewall immediately outputs the accumulated logs.
NOTICE: In actual service environment, if you run the reset firewall session table command, all session tables are cleared. This operation affects normal service running. Therefore, exercise caution when you perform this operation.
If multiple log hosts are configured, by default, the firewall circulates logs to the log hosts based on log host IDs. For example, the firewall sends the accumulated logs to the log host with ID 1 at this time and sends the accumulated logs to the log host with ID 2 at the next time. If the concurrency function is configured, the firewall sends the accumulated logs to all log hosts every time. hope to help you.