wildfire logs showing allow action for malicious url

Reply
Highlighted
L3 Networker

wildfire logs showing allow action for malicious url

Two wildifire logs (16 July and 20 July )  are showing for same url with malicious verdict and action is allow. We have checked wildfire report of both logs , all information is same (same hash value , first timestamp seen is 7 July etc. ).

If same url is identified in 7 July then why its showing in wildifre submission logs. Also why action is allow showing in second and third occurrence ?

Highlighted
Cyber Elite

Hi @Deepak_K 

In what traffic did you see these logs? If it was in smtp traffic then this is expected behaviour. In smtp paloalto sees and forwards email-links to wildfire, but cannot take actions based on urls.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!