<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wildfire Signature Based Blocks in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-signature-based-blocks/m-p/8863#M6492</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please take a look into PAN 5.0.10 fixes:&lt;/P&gt;&lt;P&gt;57763—When WildFire Action was configured as "default(Block)" in Antivirus profile, &lt;/P&gt;&lt;P&gt;block action didn't take effect as the default action was not configured internally. The &lt;/P&gt;&lt;P&gt;workaround is to configure WildFire Action as "Block" instead of "default(Block)". &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Probalby your device didn't block any of the file...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 02 Jan 2014 08:05:09 GMT</pubDate>
    <dc:creator>_slv_</dc:creator>
    <dc:date>2014-01-02T08:05:09Z</dc:date>
    <item>
      <title>Wildfire Signature Based Blocks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-signature-based-blocks/m-p/8860#M6489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hopefully a quick question - is there any way to determine whether a executable has been blocked because it was a Wildfire derived signature (for paying customers).&amp;nbsp; It may be obvious when it happens, but hard to know if it has etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would like to be able to correlate the protection afforded by the service by providing a discrete count of executables blocked, and report them seperately from 'normal' AV blocks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Dec 2013 20:46:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-signature-based-blocks/m-p/8860#M6489</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2013-12-31T20:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire Signature Based Blocks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-signature-based-blocks/m-p/8861#M6490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Lucida Grande', 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 12px;"&gt;Can you please try querying for (subtype eq wildfire) in the threat logs&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Dec 2013 21:32:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-signature-based-blocks/m-p/8861#M6490</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2013-12-31T21:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire Signature Based Blocks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-signature-based-blocks/m-p/8862#M6491</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi APackard,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or you can go for an ID between 3 and 4 million in a report.&amp;nbsp; Remembering that WildFire signatures will end up in the regular AV ID range (between 2 and 3 million - well 299999 to be precise) once processed for customers with a threat license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good Luck!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jan 2014 00:27:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-signature-based-blocks/m-p/8862#M6491</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2014-01-01T00:27:16Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire Signature Based Blocks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-signature-based-blocks/m-p/8863#M6492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please take a look into PAN 5.0.10 fixes:&lt;/P&gt;&lt;P&gt;57763—When WildFire Action was configured as "default(Block)" in Antivirus profile, &lt;/P&gt;&lt;P&gt;block action didn't take effect as the default action was not configured internally. The &lt;/P&gt;&lt;P&gt;workaround is to configure WildFire Action as "Block" instead of "default(Block)". &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Probalby your device didn't block any of the file...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jan 2014 08:05:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-signature-based-blocks/m-p/8863#M6492</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-01-02T08:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire Signature Based Blocks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-signature-based-blocks/m-p/8864#M6493</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks all, I'll check these out once I've got enough historical data with a 'paid-for' WildFire service to validate the results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One other related question - is there, or is there a plan, to annotate the WildFire report with an attribute (or similar) as to the resultant signature e.g. if I logon to my portal and check a report after a couple of hours it'll tell me which WildFire update will protect against a repeat download?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jan 2014 16:37:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-signature-based-blocks/m-p/8864#M6493</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2014-01-08T16:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire Signature Based Blocks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-signature-based-blocks/m-p/8865#M6494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Apackard,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As soon as the threat is identified in wildfire with the subscription license in place on device and automatic scheduled updates are set ( lets say an hour ) then the firewall would get the new wildfire version in the next hour. Now any further attempt of such threat traffic on the device it is logged in Wildfire logs and Threat logs. A simple search for threats in the range ( 3 to 4 million ) would give the results of the new threats being controlled.&lt;/P&gt;&lt;P&gt;The same threat will be pushed in next day updates through Antivirus content for other users who do not have wildfire license. Now from here on no more of the wildfire threat logs would be seen as from now it would be filed as antivirus threat.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps !&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jan 2014 17:25:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-signature-based-blocks/m-p/8865#M6494</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2014-01-08T17:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire Signature Based Blocks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-signature-based-blocks/m-p/8866#M6495</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;James@PANW wrote:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hi APackard,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Or you can go for an ID between 3 and 4 million in a report.&amp;nbsp; Remembering that WildFire signatures will end up in the regular AV ID range (between 2 and 3 million - well 299999 to be precise) once processed for customers with a threat license.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Good Luck!&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just for clarification on my part.&amp;nbsp; A threat ID'd by WildFire in the 3mil+ range is changed to a regular threat value after it's rolled into the standard 24-hour update?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Sep 2014 16:45:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-signature-based-blocks/m-p/8866#M6495</guid>
      <dc:creator>mrsold</dc:creator>
      <dc:date>2014-09-26T16:45:38Z</dc:date>
    </item>
  </channel>
</rss>

