<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to get WF verdicts for URLs in Automation/API Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/how-to-get-wf-verdicts-for-urls/m-p/206753#M1631</link>
    <description>&lt;P&gt;&lt;SPAN&gt;I’ve been able to successfully submit files for analysis and file hashes for verdicts,&amp;nbsp;that works fine, but I&amp;nbsp;am now trying to submit a URL for a verdict, instead of a file. So I send this:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Submit Google Link to WF using API&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;curl -F 'apikey=&amp;lt;apikey&amp;gt;' -F 'link=&lt;A href="https://www.google.com" target="_blank"&gt;https://www.google.com&lt;/A&gt;' '&lt;A href="https://wildfire.paloaltonetworks.com/publicapi/submit/link" target="_blank"&gt;https://wildfire.paloaltonetworks.com/publicapi/submit/link&lt;/A&gt;'&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Response from WF:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;lt;wildfire&amp;gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;submit-link-info&amp;gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;url&amp;gt;&lt;A href="https://www.google.com&amp;lt;/url" target="_blank"&gt;https://www.google.com&amp;lt;/url&lt;/A&gt;&amp;gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;sha256&amp;gt;ac6bb669e40e44a8d9f8f0c94dfc63734049dcf6219aac77f02edf94b9162c09&amp;lt;/sha256&amp;gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;md5&amp;gt;8ffdefbdec956b595d257f0aaeefd623&amp;lt;/md5&amp;gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/submit-link-info&amp;gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;lt;/wildfire&amp;gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;I then try to get a verdict from WF&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;curl -F 'apikey=&amp;lt;apikey&amp;gt;' -F 'hash=8ffdefbdec956b595d257f0aaeefd623' '&lt;A href="https://wildfire.paloaltonetworks.com/publicapi/get/verdict" target="_blank"&gt;https://wildfire.paloaltonetworks.com/publicapi/get/verdict&lt;/A&gt;'&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Response from WF:&lt;/P&gt;&lt;P class="p1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;&amp;lt;wildfire&amp;gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&amp;lt;get-verdict-info&amp;gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&amp;lt;sha256&amp;gt;&amp;lt;/sha256&amp;gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&amp;lt;verdict&amp;gt;-102&amp;lt;/verdict&amp;gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&amp;lt;md5&amp;gt;8ffdefbdec956b595d257f0aaeefd623&amp;lt;/md5&amp;gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;lt;/get-verdict-info&amp;gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;&amp;lt;/wildfire&amp;gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you can see&amp;nbsp;I get a “-102” response which means "&lt;SPAN&gt;unknown, cannot find sample record in the database".&lt;/SPAN&gt;&amp;nbsp; I've done this for multiple links, both HTTP and HTTPS over a number of days but always get the -102 verdict.&amp;nbsp; Am I doing this correctly to get a verdict for a URL?&amp;nbsp; I have opened a TAC case but they don't have any answers for me other than they'll get back to me and that it may take some time...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Mar 2018 20:16:03 GMT</pubDate>
    <dc:creator>Ian.Baxter</dc:creator>
    <dc:date>2018-03-21T20:16:03Z</dc:date>
    <item>
      <title>How to get WF verdicts for URLs</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/how-to-get-wf-verdicts-for-urls/m-p/206753#M1631</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I’ve been able to successfully submit files for analysis and file hashes for verdicts,&amp;nbsp;that works fine, but I&amp;nbsp;am now trying to submit a URL for a verdict, instead of a file. So I send this:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Submit Google Link to WF using API&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;curl -F 'apikey=&amp;lt;apikey&amp;gt;' -F 'link=&lt;A href="https://www.google.com" target="_blank"&gt;https://www.google.com&lt;/A&gt;' '&lt;A href="https://wildfire.paloaltonetworks.com/publicapi/submit/link" target="_blank"&gt;https://wildfire.paloaltonetworks.com/publicapi/submit/link&lt;/A&gt;'&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Response from WF:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;lt;wildfire&amp;gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;submit-link-info&amp;gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;url&amp;gt;&lt;A href="https://www.google.com&amp;lt;/url" target="_blank"&gt;https://www.google.com&amp;lt;/url&lt;/A&gt;&amp;gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;sha256&amp;gt;ac6bb669e40e44a8d9f8f0c94dfc63734049dcf6219aac77f02edf94b9162c09&amp;lt;/sha256&amp;gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;md5&amp;gt;8ffdefbdec956b595d257f0aaeefd623&amp;lt;/md5&amp;gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/submit-link-info&amp;gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;lt;/wildfire&amp;gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;I then try to get a verdict from WF&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;curl -F 'apikey=&amp;lt;apikey&amp;gt;' -F 'hash=8ffdefbdec956b595d257f0aaeefd623' '&lt;A href="https://wildfire.paloaltonetworks.com/publicapi/get/verdict" target="_blank"&gt;https://wildfire.paloaltonetworks.com/publicapi/get/verdict&lt;/A&gt;'&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Response from WF:&lt;/P&gt;&lt;P class="p1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;&amp;lt;wildfire&amp;gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&amp;lt;get-verdict-info&amp;gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&amp;lt;sha256&amp;gt;&amp;lt;/sha256&amp;gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&amp;lt;verdict&amp;gt;-102&amp;lt;/verdict&amp;gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&amp;lt;md5&amp;gt;8ffdefbdec956b595d257f0aaeefd623&amp;lt;/md5&amp;gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;lt;/get-verdict-info&amp;gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="s1"&gt;&amp;lt;/wildfire&amp;gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you can see&amp;nbsp;I get a “-102” response which means "&lt;SPAN&gt;unknown, cannot find sample record in the database".&lt;/SPAN&gt;&amp;nbsp; I've done this for multiple links, both HTTP and HTTPS over a number of days but always get the -102 verdict.&amp;nbsp; Am I doing this correctly to get a verdict for a URL?&amp;nbsp; I have opened a TAC case but they don't have any answers for me other than they'll get back to me and that it may take some time...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Mar 2018 20:16:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/how-to-get-wf-verdicts-for-urls/m-p/206753#M1631</guid>
      <dc:creator>Ian.Baxter</dc:creator>
      <dc:date>2018-03-21T20:16:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to get WF verdicts for URLs</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/how-to-get-wf-verdicts-for-urls/m-p/206778#M1632</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have also received a similar response from TAC regarding URL's or files submitted via a URL. What I do is double check with 3rd party sites such as virustotal or hybrid-analysis to see what they have to say about it as well. It's good to get second or thrid opinions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 21 Mar 2018 21:41:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/how-to-get-wf-verdicts-for-urls/m-p/206778#M1632</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-03-21T21:41:30Z</dc:date>
    </item>
  </channel>
</rss>

