<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Wildfire Submission Logs on Prisma Access in Prisma Access Articles</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-articles/wildfire-submission-logs-on-prisma-access/ta-p/448206</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;The following article walks through the steps to verify the WildFire submission logs for Prisma Access deployment via the Panorama and Explore application on the hub.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Panorama&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN style="font-weight: 400;"&gt;To view samples submitted by a firewall to a WildFire public, private, or hybrid cloud, select &lt;/SPAN&gt;&lt;STRONG&gt;Monitor&amp;nbsp; &amp;gt; Logs&amp;nbsp; &amp;gt;&amp;nbsp; WildFire Submissions&lt;/STRONG&gt;&lt;SPAN style="font-weight: 400;"&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN style="font-weight: 400;"&gt;Select the Device Group related to the Prisma Access tenant of interest.&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.jpg" style="width: 937px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37691iA5970ECC74FA4A25/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.jpg" alt="1.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN style="font-weight: 400;"&gt;When WildFire analysis of a sample is complete, the results are accessible in the WildFire Submissions logs. The submission logs include details about a given sample, including the following information:&lt;/SPAN&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN style="font-weight: 400;"&gt;The Verdict column indicates whether the sample is benign, malicious, phishing, or grayware.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN style="font-weight: 400;"&gt;The Action column indicates whether the firewall allowed or blocked the sample.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN style="font-weight: 400;"&gt;The Severity column indicates how much of a threat a sample poses to an organization using the following values: critical, high, medium, low, and informational.&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;Information on different kinds of verdicts can be found &lt;/SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/monitoring/view-and-manage-logs/log-types-and-severity-levels/wildfire-submissions-logs.html" target="_blank" rel="noopener"&gt;&lt;SPAN style="font-weight: 400;"&gt;here&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="font-weight: 400;"&gt;.&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.jpg" style="width: 931px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37692i88C4D45AD874E95E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2.jpg" alt="2.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN style="font-weight: 400;"&gt;For an entry, select the Log Details icon to open a detailed log view for each entry:&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.jpg" style="width: 465px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37693i3E435D0D94B95AC0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="3.jpg" alt="3.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Log Info &lt;/STRONG&gt;&lt;SPAN style="font-weight: 400;"&gt;provides details around the wildfire that shared the suspicious file and triggered the wildfire submission&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4.jpg" style="width: 932px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37694i2D2ED7DBA5C2B587/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="4.jpg" alt="4.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN style="font-weight: 400;"&gt;For all samples, the WildFire analysis report displays file and session details. For malware samples, the WildFire analysis report is extended to include details on the file attributes and behavior that indicates the file was malicious.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5.jpg" style="width: 921px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37695iBEC2C98F2A073CFB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="5.jpg" alt="5.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;
&lt;H2&gt;&lt;STRONG&gt;Explore App&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;To access the explore app, one must login into the &lt;/SPAN&gt;&lt;A href="https://apps.paloaltonetworks.com/apps" target="_blank" rel="noopener"&gt;&lt;SPAN style="font-weight: 400;"&gt;hub&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="font-weight: 400;"&gt;. The Explore app is available for free for all customers. A complete guide to the Explore app can be found &lt;/SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/retrieve-log-records.html" target="_blank" rel="noopener"&gt;&lt;SPAN style="font-weight: 400;"&gt;here&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="font-weight: 400;"&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;BR /&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;The following are steps to see wildfire submission logs via Explore app.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;BR /&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN style="font-weight: 400;"&gt;Select the Explore app from the list of activated apps on the hub&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="6.jpg" style="width: 930px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37696iD170E15ED8F01830/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="6.jpg" alt="6.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN style="font-weight: 400;"&gt;Select &lt;/SPAN&gt;&lt;STRONG&gt;Threat &lt;/STRONG&gt;&lt;SPAN style="font-weight: 400;"&gt;logs from the log type selection&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="7.jpg" style="width: 298px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37697i225DC973FD9AF0A2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="7.jpg" alt="7.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN style="font-weight: 400;"&gt;Subtype &lt;/SPAN&gt;&lt;STRONG&gt;wildfire &lt;/STRONG&gt;&lt;SPAN style="font-weight: 400;"&gt;represents the logs represent the results of WildFire analysis:&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="8.jpg" style="width: 504px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37698i3208640DDAFF3853/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="8.jpg" alt="8.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN style="font-weight: 400;"&gt;Click on the &lt;/SPAN&gt;&lt;STRONG&gt;‘Details' &lt;/STRONG&gt;&lt;SPAN style="font-weight: 400;"&gt;view option to look into log details:&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="9.jpg" style="width: 933px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37699i5951199C63831F39/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="9.jpg" alt="9.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN style="font-weight: 400;"&gt;The &lt;/SPAN&gt;&lt;STRONG&gt;‘Details’ &lt;/STRONG&gt;&lt;SPAN style="font-weight: 400;"&gt;view will provide information on the traffic and threat details. ‘&lt;/SPAN&gt;&lt;STRONG&gt;General’ &lt;/STRONG&gt;&lt;SPAN style="font-weight: 400;"&gt;will provide traffic information and threat details&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="10.jpg" style="width: 960px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37700i943EDEC83A5B78A6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="10.jpg" alt="10.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN style="font-weight: 400;"&gt;Click on the ‘&lt;/SPAN&gt;&lt;STRONG&gt;Details’ &lt;/STRONG&gt;&lt;SPAN style="font-weight: 400;"&gt;tab to get the hash of the file that triggered the wildfire.&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="11.jpg" style="width: 685px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37701i1EEAEF6685297F3C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="11.jpg" alt="11.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN style="font-weight: 400;"&gt;Copy the file hash from the screen&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="12.jpg" style="width: 673px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37702iCC5CF76100C587C5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="12.jpg" alt="12.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN style="font-weight: 400;"&gt;Login into &lt;/SPAN&gt;&lt;A href="https://wildfire.paloaltonetworks.com/" target="_blank" rel="noopener"&gt;&lt;SPAN style="font-weight: 400;"&gt;WildFire Portal&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="font-weight: 400;"&gt; and select Reports&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="13.jpg" style="width: 523px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37703i10B7E0797CEBEF95/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="13.jpg" alt="13.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN style="font-weight: 400;"&gt;Search using the file hash&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="14.jpg" style="width: 933px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37704iC259D1E76BFCB3B8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="14.jpg" alt="14.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN style="font-weight: 400;"&gt;Click on the ‘&lt;/SPAN&gt;&lt;STRONG&gt;Details’&lt;/STRONG&gt;&lt;SPAN style="font-weight: 400;"&gt; button to open the report in the new tab&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="15.jpg" style="width: 934px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37705i0E96AE93BB862ABA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="15.jpg" alt="15.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;BR /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Mon, 22 Nov 2021 20:21:22 GMT</pubDate>
    <dc:creator>Sai_Tumuluri</dc:creator>
    <dc:date>2021-11-22T20:21:22Z</dc:date>
    <item>
      <title>Wildfire Submission Logs on Prisma Access</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-articles/wildfire-submission-logs-on-prisma-access/ta-p/448206</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Verify the WildFire submission logs for Prisma Access deployment via the Panorama and Explore application on the hub.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Nov 2021 20:21:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-articles/wildfire-submission-logs-on-prisma-access/ta-p/448206</guid>
      <dc:creator>Sai_Tumuluri</dc:creator>
      <dc:date>2021-11-22T20:21:22Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire Submission Logs on Prisma Access</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-articles/wildfire-submission-logs-on-prisma-access/tac-p/581988#M29</link>
      <description>&lt;P&gt;Which region will the WF cloud service sent by Prisma Access ?&lt;/P&gt;&lt;P&gt;Reports cannot be viewed on global portal configured with template&lt;BR /&gt;I was able to confirm this on another portal.&lt;/P&gt;&lt;P&gt;How do Prisma Access decide on a destination?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you know, please let me know.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 06:09:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-articles/wildfire-submission-logs-on-prisma-access/tac-p/581988#M29</guid>
      <dc:creator>MakotoT</dc:creator>
      <dc:date>2024-03-28T06:09:49Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire Submission Logs on Prisma Access</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-articles/wildfire-submission-logs-on-prisma-access/tac-p/581991#M30</link>
      <description>&lt;P&gt;According to the PDF at the following URL, it is determined by the Compute Location of Prisma Access.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/resources/datasheets/privacy-prisma-access" target="_blank"&gt;https://www.paloaltonetworks.com/resources/datasheets/privacy-prisma-access&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 06:24:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-articles/wildfire-submission-logs-on-prisma-access/tac-p/581991#M30</guid>
      <dc:creator>s-hamamoto</dc:creator>
      <dc:date>2024-03-28T06:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire Submission Logs on Prisma Access</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-articles/wildfire-submission-logs-on-prisma-access/tac-p/581994#M31</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thank you very much for helping me.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 06:58:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-articles/wildfire-submission-logs-on-prisma-access/tac-p/581994#M31</guid>
      <dc:creator>MakotoT</dc:creator>
      <dc:date>2024-03-28T06:58:46Z</dc:date>
    </item>
  </channel>
</rss>

