<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Some Applications not being submitted to wildfire in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/some-applications-not-being-submitted-to-wildfire/m-p/150570#M49978</link>
    <description>&lt;P&gt;FYI,&lt;/P&gt;&lt;P&gt;Your not going to see a submission log for something that has already been identified since your local firewall database already knows about the file, that's why the wildfire test PE is generated per request so that you actually see a submission log. If you are copying an already identified known bad file it can skip the submission process and simply take action based on what it already knows about the file.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;**EDIT**&lt;/P&gt;&lt;P&gt;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10238"&gt;@santonic&lt;/a&gt;&amp;nbsp;already mentioned this...my bad&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 31 Mar 2017 12:54:27 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-03-31T12:54:27Z</dc:date>
    <item>
      <title>Some Applications not being submitted to wildfire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/some-applications-not-being-submitted-to-wildfire/m-p/150487#M49963</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;&lt;BR /&gt;I am testing my wildfire configuration .&lt;BR /&gt;&lt;BR /&gt;1- When I download wildfire test PE file&amp;nbsp; , I get an entry under Wildfire submission log &amp;amp; data filtering log.&lt;BR /&gt;2- I intend to test if copying the PE file is also caught by wildfire , so I download a new PE file from wildfire site&amp;nbsp; on a machine that is not protected by wildfire , then copy it across to a machine in another zone . the rule has wildfire and block file&amp;nbsp; . this time we do not get any submission but we see a record under data-filtering.&lt;BR /&gt;why there is no wild fire submissions in this case ?&lt;BR /&gt;&lt;BR /&gt;in first approach , the application is web-browsing&lt;BR /&gt;second approach , the application is ms-ds-smb&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible that some applications are excluded from wildfire ? it seems only Risk5 apps are being sent . is there a place to change the behavior ?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 22:47:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/some-applications-not-being-submitted-to-wildfire/m-p/150487#M49963</guid>
      <dc:creator>akhalighi</dc:creator>
      <dc:date>2017-03-30T22:47:39Z</dc:date>
    </item>
    <item>
      <title>Re: Some Applications not being submitted to wildfire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/some-applications-not-being-submitted-to-wildfire/m-p/150525#M49966</link>
      <description>&lt;P&gt;Check the threat logs for AV events. File is sent to WF only when WF doesn't know that file yet. If WF has already seen that file it only replies with verdict or apropriate signature, there's no need to upload file again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2017 06:13:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/some-applications-not-being-submitted-to-wildfire/m-p/150525#M49966</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2017-03-31T06:13:38Z</dc:date>
    </item>
    <item>
      <title>Re: Some Applications not being submitted to wildfire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/some-applications-not-being-submitted-to-wildfire/m-p/150533#M49968</link>
      <description>&lt;P&gt;"the rule has wildfire and block file"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;are you blocking the file copy? a blocked session will not be uploaded to wildfire as the file is never completely transferred&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2017 07:05:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/some-applications-not-being-submitted-to-wildfire/m-p/150533#M49968</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-03-31T07:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: Some Applications not being submitted to wildfire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/some-applications-not-being-submitted-to-wildfire/m-p/150570#M49978</link>
      <description>&lt;P&gt;FYI,&lt;/P&gt;&lt;P&gt;Your not going to see a submission log for something that has already been identified since your local firewall database already knows about the file, that's why the wildfire test PE is generated per request so that you actually see a submission log. If you are copying an already identified known bad file it can skip the submission process and simply take action based on what it already knows about the file.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;**EDIT**&lt;/P&gt;&lt;P&gt;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10238"&gt;@santonic&lt;/a&gt;&amp;nbsp;already mentioned this...my bad&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2017 12:54:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/some-applications-not-being-submitted-to-wildfire/m-p/150570#M49978</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-03-31T12:54:27Z</dc:date>
    </item>
  </channel>
</rss>

