<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Antivirus profile question, wildfire action? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-profile-question-wildfire-action/m-p/35357#M25975</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Courier New'; color: #1022d2;"&gt;Hello Sir,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Courier New'; color: #1022d2;"&gt;You can define different actions for standard antivirus signatures (Action column) and signatures generated by the WildFire system (WildFire Action column). This is applicable if you have a valid Wildfire license on your PAN firewall. Some environments may have requirements for a longer soak time for antivirus signatures, so this option enables the ability to set different actions for the two antivirus signature types provided by Palo Alto Networks. For example, the standard antivirus signatures go through a longer soak period before being released (24 hours), versus WildFire signatures, which can be generated and released within 15 minutes after a threat is detected. Because of this, you may want to choose the alert action on WildFire signatures instead of blocking.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Courier New'; color: #1022d2;"&gt;Hope this helps.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Courier New'; color: #1022d2;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 May 2014 15:12:20 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-05-06T15:12:20Z</dc:date>
    <item>
      <title>Antivirus profile question, wildfire action?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-profile-question-wildfire-action/m-p/35356#M25974</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a question about how to configure an antivirus profile. When try to define Decoders and actions can see a tab for "Wildfire Action" and that's where my confusion appear. what's the purpose of this tab? that implies that if I select block, all the files were be blocked? ? As far as I know wildfire is an "on the cloud" scanning system but in the documentation of panOS 6.0 I can see this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/13269_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it's possible that wildifre have an internal database to check the files without the need to send it to the cloud?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/13270_pastedImage_1.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 May 2014 14:50:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-profile-question-wildfire-action/m-p/35356#M25974</guid>
      <dc:creator>JoseMartinez</dc:creator>
      <dc:date>2014-05-06T14:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus profile question, wildfire action?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-profile-question-wildfire-action/m-p/35357#M25975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Courier New'; color: #1022d2;"&gt;Hello Sir,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Courier New'; color: #1022d2;"&gt;You can define different actions for standard antivirus signatures (Action column) and signatures generated by the WildFire system (WildFire Action column). This is applicable if you have a valid Wildfire license on your PAN firewall. Some environments may have requirements for a longer soak time for antivirus signatures, so this option enables the ability to set different actions for the two antivirus signature types provided by Palo Alto Networks. For example, the standard antivirus signatures go through a longer soak period before being released (24 hours), versus WildFire signatures, which can be generated and released within 15 minutes after a threat is detected. Because of this, you may want to choose the alert action on WildFire signatures instead of blocking.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Courier New'; color: #1022d2;"&gt;Hope this helps.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Courier New'; color: #1022d2;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 May 2014 15:12:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-profile-question-wildfire-action/m-p/35357#M25975</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-05-06T15:12:20Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus profile question, wildfire action?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-profile-question-wildfire-action/m-p/35358#M25976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;Hulk, could You tell us how to check in thread log is a WildFire signatures triggered for any kind of thread?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 May 2014 06:34:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-profile-question-wildfire-action/m-p/35358#M25976</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-05-07T06:34:46Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus profile question, wildfire action?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-profile-question-wildfire-action/m-p/35359#M25977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wildfire logs will be available under Monitor &amp;gt; Logs &amp;gt; wildfire only. &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;not&lt;/SPAN&gt; under threat logs).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 May 2014 15:16:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-profile-question-wildfire-action/m-p/35359#M25977</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-05-07T15:16:49Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus profile question, wildfire action?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-profile-question-wildfire-action/m-p/35360#M25978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hulk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm a bit confused.&lt;/P&gt;&lt;P&gt;In Monitor&amp;gt;Logs I have "WildFire Submissions" log with just two entries from april. I hope thats because my users are not downloading a lot of malwares from internet.&lt;/P&gt;&lt;P&gt;One of them has details:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2014-05-08_101820.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/13295_2014-05-08_101820.png" style="width: 620px; height: 203px;" /&gt;&lt;/P&gt;&lt;P&gt;In my opinion this is log which collecting data about files that are not known by WildFire cloud and passed my device.&lt;/P&gt;&lt;P&gt;I'm looking for files that was blocked by my device o based on wildfire updates (which I gets every 15 minuts)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 May 2014 08:22:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-profile-question-wildfire-action/m-p/35360#M25978</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-05-08T08:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus profile question, wildfire action?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-profile-question-wildfire-action/m-p/35361#M25979</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are also looking for something that shows traffic being blocked because of a WildFire update.&amp;nbsp; Has anyone found a way to get this type of report?&amp;nbsp; Trying to find a way to justify the purchase to management.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jul 2014 18:18:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-profile-question-wildfire-action/m-p/35361#M25979</guid>
      <dc:creator>jhughson1</dc:creator>
      <dc:date>2014-07-31T18:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: Antivirus profile question, wildfire action?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/antivirus-profile-question-wildfire-action/m-p/35362#M25980</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From my understanding, there is no way to figure out that traffic was blocked by antivirus signature or wildfire signature from threat log (especially "type" field. this will be 'virus' in both case).&lt;/P&gt;&lt;P&gt;Though I think you can figure out by looking at threat ID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refer to following KB: &lt;A href="https://live.paloaltonetworks.com/docs/DOC-7299"&gt;Threat ID Ranges in the Palo Alto Networks Content Database&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, if you hit any virus with TID is between &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;2000000 - 3000000&lt;/SPAN&gt;, then this might be hit to antivirus signature. But if it is between &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;3000000 - 3100000, then this might be wildfire signature.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Isn't it?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Aug 2014 04:13:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/antivirus-profile-question-wildfire-action/m-p/35362#M25980</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2014-08-01T04:13:27Z</dc:date>
    </item>
  </channel>
</rss>

