Some Applications not being submitted to wildfire

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Some Applications not being submitted to wildfire

L2 Linker

Hello

I am testing my wildfire configuration .

1- When I download wildfire test PE file  , I get an entry under Wildfire submission log & data filtering log.
2- I intend to test if copying the PE file is also caught by wildfire , so I download a new PE file from wildfire site  on a machine that is not protected by wildfire , then copy it across to a machine in another zone . the rule has wildfire and block file  . this time we do not get any submission but we see a record under data-filtering.
why there is no wild fire submissions in this case ?

in first approach , the application is web-browsing
second approach , the application is ms-ds-smb

 

Is it possible that some applications are excluded from wildfire ? it seems only Risk5 apps are being sent . is there a place to change the behavior ?

3 REPLIES 3

L6 Presenter

Check the threat logs for AV events. File is sent to WF only when WF doesn't know that file yet. If WF has already seen that file it only replies with verdict or apropriate signature, there's no need to upload file again.

 

Cyber Elite
Cyber Elite

"the rule has wildfire and block file"

 

are you blocking the file copy? a blocked session will not be uploaded to wildfire as the file is never completely transferred

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Cyber Elite
Cyber Elite

FYI,

Your not going to see a submission log for something that has already been identified since your local firewall database already knows about the file, that's why the wildfire test PE is generated per request so that you actually see a submission log. If you are copying an already identified known bad file it can skip the submission process and simply take action based on what it already knows about the file. 

 

 

**EDIT**

and @santonic already mentioned this...my bad 

  • 1976 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!