Been googling a bit, but I'm not finding what the difference is between a "rogue AP" (I get that) and a "malicious rogue AP". Also the logging is odd - I get log events of the rogue AP going away, but no mention of it appearing. Log example:
2017/03/09 14:15:09 | High | A Malicious Rogue[40:5d:82:12:5d:93] detection by AP[1c:b9:c4:35:eb:e0] goes away
That MAC belongs to a Netgear device, so I'm assuming it's some consumer router. It would be helpful if an SSID was logged as well...