Understanding Wildfire logs

Reply
Highlighted
L4 Transporter

Understanding Wildfire logs

image.pngThis screenshot is from the wilfire tab. Why I see this informational block and high alert.


Accepted Solutions
Highlighted
L5 Sessionator

Re: Understanding Wildfire logs

This is expected behavior and by design.

 

Informational - the threat (file) was blocked by a Wildfire-virus signature and therefore the firewall alerts the admin at an informational level because the threat was mitigated.

 

High - the threat (file) was passed by the firewall and not blocked by a Wildfire-virus or Antivirus signature.  This could be due to the configuration or due to the fact that a virus signature to detect and block the file does not exist.

 

You can derive additional context by also reviewing the corresponding Threat logs relevant to the two Wildfire log entries in your screenshot.

View solution in original post


All Replies
Highlighted
L5 Sessionator

Re: Understanding Wildfire logs

This is expected behavior and by design.

 

Informational - the threat (file) was blocked by a Wildfire-virus signature and therefore the firewall alerts the admin at an informational level because the threat was mitigated.

 

High - the threat (file) was passed by the firewall and not blocked by a Wildfire-virus or Antivirus signature.  This could be due to the configuration or due to the fact that a virus signature to detect and block the file does not exist.

 

You can derive additional context by also reviewing the corresponding Threat logs relevant to the two Wildfire log entries in your screenshot.

View solution in original post

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!