Two wildifire logs (16 July and 20 July ) are showing for same url with malicious verdict and action is allow. We have checked wildfire report of both logs , all information is same (same hash value , first timestamp seen is 7 July etc. ).
If same url is identified in 7 July then why its showing in wildifre submission logs. Also why action is allow showing in second and third occurrence ?
In what traffic did you see these logs? If it was in smtp traffic then this is expected behaviour. In smtp paloalto sees and forwards email-links to wildfire, but cannot take actions based on urls.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!