NSX UI > Networking > NAT >DNAT Rule's
You can see logging in the /var/log/firewallpkt.log even though logging for DNAT above is set to No
Example
And observed in the /var/log/syslog
NSX 3.2.x
NSX 4.2.x
This is caused by the corresponding Gateway Firewall Rule being logged having matched criteria in the flow and applied to the same interface at the DNAT/SNAT rule.
Check to see if this correspondence is correct by logging into the Edge and running command 'get firewall <UUID> connection'
Example shows in a live flow format and the rule id will matched with the corresponding DNAT rule [Gateway Firewall Rule ID = 11252] & [DNAT Rule ID = 536870915]
Example or rule settings shows rule 11252 is set to logging
Use command 'get firewall <UUID> connection' to get a live connection flow and match rule id to corresponding DNAT/SNAT rule.
Troubleshooting, Logging information, and Commands for Edge Firewall. Follow steps to get the proper UUID for command 'get firewall <UUID> connection'
https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-2/administration-guide/security/troubleshooting-firewall/troubleshooting-gateway-firewall.html