- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-20-2017 01:27 AM
Hi Sharief
I think you were looking at the wildfire submission log at first
This log is a representation of which files were processed by wildfire and uploaded to the wildfire cloud for analysis. For every file uploaded the verdict is only added afterward, when the analysis is complete. (files that are already known will not be uploaded and will be processes by your AntiVirus profile settings) After a file has reached a verdict of malicious, signatures are created and made available through the wildfire dynamic updates.
Once downloaded and installed, this infected file can now be blocked and a Treat log entry will be generated (not for the first time the file is seen, as there is no signature yet and the file is not blocked)
so if you see a malicious file via the wildfire log but nothing in threat, the file was only seen once