<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wildfire event through the REST API in Automation/API Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/wildfire-event-through-the-rest-api/m-p/45285#M1039</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has the URI you mentioned already been valid?&lt;/P&gt;&lt;P&gt;I tried following command today but no luck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-------------------------------&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;$ curl -i -k -F device_id=001606000xxx -F report_id=417xxx -F format=xml &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://wildfire.paloaltonetworks.com/publicapi/report"&gt;https://wildfire.paloaltonetworks.com/publicapi/report&lt;/A&gt;&lt;/P&gt;&lt;P&gt;HTTP/1.1 100 Continue&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTTP/1.1 400 Bad Request&lt;/P&gt;&lt;P&gt;Server: nginx/1.0.9&lt;/P&gt;&lt;P&gt;Date: Thu, 11 Jul 2013 07:22:30 GMT&lt;/P&gt;&lt;P&gt;Content-Type: text/html&lt;/P&gt;&lt;P&gt;Transfer-Encoding: chunked&lt;/P&gt;&lt;P&gt;Connection: keep-alive&lt;/P&gt;&lt;P&gt;X-Powered-By: PHP/5.3.6&lt;/P&gt;&lt;P&gt;-------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also tried with wget to check if the curl I am using is something wrong but almost same result.&lt;/P&gt;&lt;P&gt;-------------------------------&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;$ wget --no-check-certificate --post-data 'device_id=001606000xxx&amp;amp;report_id=417xxx&amp;amp;format=xml' &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://wildfire.paloaltonetworks.com/publicapi/report"&gt;https://wildfire.paloaltonetworks.com/publicapi/report&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;--2013-07-11 08:25:46--&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://wildfire.paloaltonetworks.com/publicapi/report"&gt;https://wildfire.paloaltonetworks.com/publicapi/report&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Resolving wildfire.paloaltonetworks.com... 54.241.16.153&lt;/P&gt;&lt;P&gt;Connecting to wildfire.paloaltonetworks.com|54.241.16.153|:443... connected.&lt;/P&gt;&lt;P&gt;WARNING: certificate common name `*.wildfire.paloaltonetworks.com' doesn't match requested host name `wildfire.paloaltonetworks.com'.&lt;/P&gt;&lt;P&gt;HTTP request sent, awaiting response... 400 Bad Request&lt;/P&gt;&lt;P&gt;2013-07-11 08:25:47 ERROR 400: Bad Request.&lt;/P&gt;&lt;P&gt;-------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any mistakes I am making?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 11 Jul 2013 07:33:36 GMT</pubDate>
    <dc:creator>tmyzw</dc:creator>
    <dc:date>2013-07-11T07:33:36Z</dc:date>
    <item>
      <title>Wildfire event through the REST API</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/wildfire-event-through-the-rest-api/m-p/45281#M1035</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been looking at the RESTful XML API in order to retrieve logs, and have noticed that the API returns traffic and threat logs, but it does not return wildfire logs.&lt;/P&gt;&lt;P&gt;To retrieve threat logs I provide type=logs and log-type=threat as parameters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wildfire logs show up with type=THREAT and subType=wildfire when retrieved through syslog. Shouldn't they then be return similarly through the REST API?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 May 2013 13:41:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/wildfire-event-through-the-rest-api/m-p/45281#M1035</guid>
      <dc:creator>wissa</dc:creator>
      <dc:date>2013-05-01T13:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire event through the REST API</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/wildfire-event-through-the-rest-api/m-p/45282#M1036</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wildfire logs cannot be retrieved from the API using the 'log-type=threat' option. A new 'log-type=wildfire' option is being added for this in upcoming PAN-OS 5.0.x software update.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 May 2013 19:15:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/wildfire-event-through-the-rest-api/m-p/45282#M1036</guid>
      <dc:creator>SRA</dc:creator>
      <dc:date>2013-05-01T19:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire event through the REST API</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/wildfire-event-through-the-rest-api/m-p/45283#M1037</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, savasarala. Will the file hash be available with the new option for wildfire logs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 May 2013 04:20:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/wildfire-event-through-the-rest-api/m-p/45283#M1037</guid>
      <dc:creator>wissa</dc:creator>
      <dc:date>2013-05-02T04:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire event through the REST API</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/wildfire-event-through-the-rest-api/m-p/45284#M1038</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi wissa,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a bug fix to address accessing WildFire logs via the API that is planned for the upcoming maintenance release 5.0.5, due soon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The hash is not available within the WildFire logs on the device, but can be accessed via the WildFire API.&amp;nbsp; In order to retrieve file hash (along with other WildFire forensics details), &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;you can use the WildFire logs on the device and turn into WildFire API queries.&amp;nbsp; We recently added a new WildFire API method used to query based on device id (S/N) and report ID in the WildFire reports (labeled as threat ID or "tid").&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;A demonstration of the API query as a CURL command is provided below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;curl -i -k -F device_id=[SERIAL NUMBER] -F report_id=[TID FROM LOG] -F format=xml &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://wildfire.paloaltonetworks.com/publicapi/report"&gt;https://wildfire.paloaltonetworks.com/publicapi/report&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;WildFire logs can be exported to provide this information using log export or log forwarding.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;SPAN&gt;The full API manual (not including the above new method) is available at: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://wildfire.paloaltonetworks.com/Wildfire/Home/APIProgrammingGuide"&gt;https://wildfire.paloaltonetworks.com/Wildfire/Home/APIProgrammingGuide&lt;/A&gt;&lt;SPAN&gt;.&amp;nbsp; Documentation will be updated soon to include this new API method.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 May 2013 03:55:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/wildfire-event-through-the-rest-api/m-p/45284#M1038</guid>
      <dc:creator>tettema</dc:creator>
      <dc:date>2013-05-03T03:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire event through the REST API</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/wildfire-event-through-the-rest-api/m-p/45285#M1039</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has the URI you mentioned already been valid?&lt;/P&gt;&lt;P&gt;I tried following command today but no luck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-------------------------------&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;$ curl -i -k -F device_id=001606000xxx -F report_id=417xxx -F format=xml &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://wildfire.paloaltonetworks.com/publicapi/report"&gt;https://wildfire.paloaltonetworks.com/publicapi/report&lt;/A&gt;&lt;/P&gt;&lt;P&gt;HTTP/1.1 100 Continue&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTTP/1.1 400 Bad Request&lt;/P&gt;&lt;P&gt;Server: nginx/1.0.9&lt;/P&gt;&lt;P&gt;Date: Thu, 11 Jul 2013 07:22:30 GMT&lt;/P&gt;&lt;P&gt;Content-Type: text/html&lt;/P&gt;&lt;P&gt;Transfer-Encoding: chunked&lt;/P&gt;&lt;P&gt;Connection: keep-alive&lt;/P&gt;&lt;P&gt;X-Powered-By: PHP/5.3.6&lt;/P&gt;&lt;P&gt;-------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also tried with wget to check if the curl I am using is something wrong but almost same result.&lt;/P&gt;&lt;P&gt;-------------------------------&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;$ wget --no-check-certificate --post-data 'device_id=001606000xxx&amp;amp;report_id=417xxx&amp;amp;format=xml' &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://wildfire.paloaltonetworks.com/publicapi/report"&gt;https://wildfire.paloaltonetworks.com/publicapi/report&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;--2013-07-11 08:25:46--&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://wildfire.paloaltonetworks.com/publicapi/report"&gt;https://wildfire.paloaltonetworks.com/publicapi/report&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Resolving wildfire.paloaltonetworks.com... 54.241.16.153&lt;/P&gt;&lt;P&gt;Connecting to wildfire.paloaltonetworks.com|54.241.16.153|:443... connected.&lt;/P&gt;&lt;P&gt;WARNING: certificate common name `*.wildfire.paloaltonetworks.com' doesn't match requested host name `wildfire.paloaltonetworks.com'.&lt;/P&gt;&lt;P&gt;HTTP request sent, awaiting response... 400 Bad Request&lt;/P&gt;&lt;P&gt;2013-07-11 08:25:47 ERROR 400: Bad Request.&lt;/P&gt;&lt;P&gt;-------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any mistakes I am making?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jul 2013 07:33:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/wildfire-event-through-the-rest-api/m-p/45285#M1039</guid>
      <dc:creator>tmyzw</dc:creator>
      <dc:date>2013-07-11T07:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire event through the REST API</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/wildfire-event-through-the-rest-api/m-p/45286#M1040</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you are missing the apikey.&amp;nbsp; I use -d in the below because you don't need a &lt;CODE&gt;multipart/form-data request, but -F will work also.&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;KEY=xxx&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;$ curl -i -d "apikey=$KEY" -d device_id=00xxx -d report_id=247406568 &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://wildfire.paloaltonetworks.com/publicapi/report"&gt;https://wildfire.paloaltonetworks.com/publicapi/report&lt;/A&gt;&lt;/P&gt;&lt;P&gt;HTTP/1.1 200 OK&lt;/P&gt;&lt;P&gt;Server: nginx/1.0.9&lt;/P&gt;&lt;P&gt;Date: Sat, 13 Jul 2013 00:23:43 GMT&lt;/P&gt;&lt;P&gt;Content-Type: text/xml; charset=utf-8&lt;/P&gt;&lt;P&gt;Transfer-Encoding: chunked&lt;/P&gt;&lt;P&gt;Connection: keep-alive&lt;/P&gt;&lt;P&gt;X-Powered-By: PHP/5.3.6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;wildfire&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;lt;report&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;version&amp;gt;0.1&amp;lt;/version&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;task&amp;gt;353397118&amp;lt;/task&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;sha256&amp;gt;8122940e894a0dafa2fc75310909d83646dfdea2e30845511c1dc697be7b779c&amp;lt;/sha256&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;md5&amp;gt;eadf7415867bfaa3dc4c34c1016f6440&amp;lt;/md5&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;size&amp;gt;707120&amp;lt;/size&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;malware&amp;gt;yes&amp;lt;/malware&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 Jul 2013 00:32:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/wildfire-event-through-the-rest-api/m-p/45286#M1040</guid>
      <dc:creator>ksteves1</dc:creator>
      <dc:date>2013-07-13T00:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire event through the REST API</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/wildfire-event-through-the-rest-api/m-p/45287#M1041</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It worked as expected!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Takahiro&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 Jul 2013 01:29:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/wildfire-event-through-the-rest-api/m-p/45287#M1041</guid>
      <dc:creator>tmyzw</dc:creator>
      <dc:date>2013-07-13T01:29:51Z</dc:date>
    </item>
  </channel>
</rss>

