It's not so easy to figure it out, because the IP's changes really often. In my test, i had different IPs. I only see the address, when the fqdn object is in the policy. Between both commands are approximately 30 seconds. So, I'm not sure whether i am to slowly or the SRX resolution list is false. It seems like the SRX dns resolution list...
show security flow session source-prefix 10.39.198.2
node0:
--------------------------------------------------------------------------
Session ID: 939274, Policy name: pol_DMZ-MDM_to_Untrust-ISP1_Apple_feedback/24, State: Active, Timeout: 1794, Valid
In: 10.39.198.2/51393 --> 17.188.135.152/2196;tcp, Conn Tag: 0x0, If: reth1.198, Pkts: 2, Bytes: 92,
Out: 17.188.135.152/2196 --> 185.46.137.110/55929;tcp, Conn Tag: 0x0, If: reth0.2001, Pkts: 1, Bytes: 52,
Total sessions: 1
show security policies policy-name pol_DMZ-MDM_to_Untrust-ISP1_Apple_feedback detail
node0:
--------------------------------------------------------------------------
Policy: pol_DMZ-MDM_to_Untrust-ISP1_Apple_feedback, action-type: permit, State: enabled, Index: 24, Scope Policy: 0
Policy Type: Configured
Sequence number: 1
From zone: DMZ-MDM, To zone: Untrust-ISP1
Source addresses:
H_Airwatch-MDM_10.39.198.2: 10.39.198.2/32
Destination addresses:
H_feedback.push.apple.com: 17.188.142.26/32
H_feedback.push.apple.com: 17.188.129.25/32
H_feedback.push.apple.com: 17.188.131.27/32
H_feedback.push.apple.com: 17.188.142.27/32
H_feedback.push.apple.com: 17.188.133.149/32
H_feedback.push.apple.com: 17.188.135.22/32
H_feedback.push.apple.com: 17.188.139.28/32
H_feedback.push.apple.com: 17.188.132.25/32
Application: S_TCP_2196
IP protocol: tcp, ALG: 0, Inactivity timeout: 1800
Source port range: [0-0]
Destination port range: [2196-2196]
Per policy TCP Options: SYN check: No, SEQ check: No, Window scale: No
best,
steffi