Empty WildFire log after upgrade

cancel
Showing results for 
Search instead for 
Did you mean: 

Empty WildFire log after upgrade

L4 Transporter

Hi

Few days ago I upgradded my devices from 4.1.10 to 5.0.3

I found new log caled WildFire, but it's empty.

Yestarday I got email from WildFire with report that someone from my network downloaded malware. So Im sure that this incident should be in log - but it isn't - why?

Do I need to configure something?

Regards

Slawek

1 ACCEPTED SOLUTION

Accepted Solutions

L5 Sessionator

As Phil says, you need wildfire subscription on your device.

Then you can check connection between your device and wildfire portal as follow.

admin@PA-200> test wildfire registration

This test may take a few minutes to finish. Do you want to continue? (y or n)

Test wildfire

        wildfire registration:         successful

        download server list:          successful

        select the best server:        jp-s1.wildfire.paloaltonetworks.com

admin@PA-200>

The following commands are also helpful.

> show wildfire status

To record benign logs, you need to configure following command.

# set deviceconfig setting wildfire report-benign-file yes

# commit

Regards,

View solution in original post

3 REPLIES 3

L4 Transporter

Hi Slawek,

If you do not have a valid Wildfire subscription then the logs will not be populated but you will still get the email alerts as you were getting when you were on 4.1.10.  Hope this helps.

Phil

L5 Sessionator

As Phil says, you need wildfire subscription on your device.

Then you can check connection between your device and wildfire portal as follow.

admin@PA-200> test wildfire registration

This test may take a few minutes to finish. Do you want to continue? (y or n)

Test wildfire

        wildfire registration:         successful

        download server list:          successful

        select the best server:        jp-s1.wildfire.paloaltonetworks.com

admin@PA-200>

The following commands are also helpful.

> show wildfire status

To record benign logs, you need to configure following command.

# set deviceconfig setting wildfire report-benign-file yes

# commit

Regards,

Thank you

You are correct - I havent WF licence.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!