<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question about threat logs - Type wildfire-virus in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-threat-logs-type-wildfire-virus/m-p/63392#M38156</link>
    <description>&lt;P&gt;1. What is the action for other decoders than smtp?&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Action: all block; WildFire Action: all&amp;nbsp;block&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. The policy to which the AV profile is applied. Does it process other kind of traffic?&lt;/P&gt;&lt;P&gt;&lt;EM&gt;no diffrent AV profile is&amp;nbsp;used between other rules. but the policy&amp;nbsp;for smtp only allow smtp (app-default)&amp;nbsp;traffic.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. If it does, do the other traffic actually carry any threat data?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;threat data on other policies are there (except wildfire-virus)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4. Do you have any exceptions applied under applications tab in the screenshot above?&lt;/P&gt;&lt;P&gt;&lt;EM&gt;nope&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Aug 2015 13:32:56 GMT</pubDate>
    <dc:creator>Hithead</dc:creator>
    <dc:date>2015-08-20T13:32:56Z</dc:date>
    <item>
      <title>Question about threat logs - Type wildfire-virus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-threat-logs-type-wildfire-virus/m-p/63337#M38125</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;just wondering why I see in our threat logs entries with the type&amp;nbsp;wildfire-virus only for the application smtp...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(I would&amp;nbsp;like to post some&amp;nbsp;screenshots, but&amp;nbsp;I cant find the upload button?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;What is the type wildfire-virus standing for? And where can I enable it for other applications as well?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2015 14:26:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-about-threat-logs-type-wildfire-virus/m-p/63337#M38125</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2015-08-19T14:26:03Z</dc:date>
    </item>
    <item>
      <title>Re: Question about threat logs - Type wildfire-virus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-threat-logs-type-wildfire-virus/m-p/63387#M38153</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/2357"&gt;@Hithead﻿&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;wildfire-virus is a subtype used for wildfire signatures delivered using wildfire signature database, to differentiate from regular anti-virus signatures.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In short,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;AV signatures are identified using subtype virus.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Wildfire signatures are identified using subtype wildfire-virus.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope this helps.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank You.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2015 12:14:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-about-threat-logs-type-wildfire-virus/m-p/63387#M38153</guid>
      <dc:creator>prb</dc:creator>
      <dc:date>2015-08-20T12:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: Question about threat logs - Type wildfire-virus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-threat-logs-type-wildfire-virus/m-p/63388#M38154</link>
      <description>&lt;P&gt;thank you very much vor your response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I'm still wondering, why I see wildfire-virus logs&amp;nbsp;only in combination with smtp... I guess wildfire-virus should also track and identify threats on other protocols/applications as well...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2015 12:24:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-about-threat-logs-type-wildfire-virus/m-p/63388#M38154</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2015-08-20T12:24:22Z</dc:date>
    </item>
    <item>
      <title>Re: Question about threat logs - Type wildfire-virus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-threat-logs-type-wildfire-virus/m-p/63390#M38155</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/2357"&gt;@Hithead﻿&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sure it should inspect traffic from other decoders as well.&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10i7D71E7F0FB5087FE/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="wildfire.JPG" title="wildfire.JPG" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wildfire action is set using the highlighted column in anti-virus profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You might need to check lot of other factors -&lt;/P&gt;&lt;P&gt;1. What is the action for other decoders than smtp?&lt;/P&gt;&lt;P&gt;2. The policy to which the AV profile is applied. Does it process other kind of traffic?&lt;/P&gt;&lt;P&gt;3. If it does, do the other traffic actually carry any threat data?&amp;nbsp;&lt;/P&gt;&lt;P&gt;4. Do you have any exceptions applied under applications tab in the screenshot above?&lt;/P&gt;&lt;P&gt;Etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank You.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2015 12:47:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-about-threat-logs-type-wildfire-virus/m-p/63390#M38155</guid>
      <dc:creator>prb</dc:creator>
      <dc:date>2015-08-20T12:47:50Z</dc:date>
    </item>
    <item>
      <title>Re: Question about threat logs - Type wildfire-virus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-threat-logs-type-wildfire-virus/m-p/63392#M38156</link>
      <description>&lt;P&gt;1. What is the action for other decoders than smtp?&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Action: all block; WildFire Action: all&amp;nbsp;block&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. The policy to which the AV profile is applied. Does it process other kind of traffic?&lt;/P&gt;&lt;P&gt;&lt;EM&gt;no diffrent AV profile is&amp;nbsp;used between other rules. but the policy&amp;nbsp;for smtp only allow smtp (app-default)&amp;nbsp;traffic.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. If it does, do the other traffic actually carry any threat data?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;threat data on other policies are there (except wildfire-virus)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4. Do you have any exceptions applied under applications tab in the screenshot above?&lt;/P&gt;&lt;P&gt;&lt;EM&gt;nope&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2015 13:32:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-about-threat-logs-type-wildfire-virus/m-p/63392#M38156</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2015-08-20T13:32:56Z</dc:date>
    </item>
  </channel>
</rss>

