How does the dns-wildfire threat category work? I've seen a log entry, but there isn't any traffic to the sinkhole IP. The action is sinkhole and reported as generic:malicious.domain1. I have confirmed that sinkhole does work for regular threat category dns and is reported as Suspicious DNS Query (generic:malicious.domain2).
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The Live Community thanks you for your participation!