Understanding Wildfire logs

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Understanding Wildfire logs

L4 Transporter

image.pngThis screenshot is from the wilfire tab. Why I see this informational block and high alert.

1 accepted solution

Accepted Solutions

L5 Sessionator

This is expected behavior and by design.

 

Informational - the threat (file) was blocked by a Wildfire-virus signature and therefore the firewall alerts the admin at an informational level because the threat was mitigated.

 

High - the threat (file) was passed by the firewall and not blocked by a Wildfire-virus or Antivirus signature.  This could be due to the configuration or due to the fact that a virus signature to detect and block the file does not exist.

 

You can derive additional context by also reviewing the corresponding Threat logs relevant to the two Wildfire log entries in your screenshot.

View solution in original post

1 REPLY 1

L5 Sessionator

This is expected behavior and by design.

 

Informational - the threat (file) was blocked by a Wildfire-virus signature and therefore the firewall alerts the admin at an informational level because the threat was mitigated.

 

High - the threat (file) was passed by the firewall and not blocked by a Wildfire-virus or Antivirus signature.  This could be due to the configuration or due to the fact that a virus signature to detect and block the file does not exist.

 

You can derive additional context by also reviewing the corresponding Threat logs relevant to the two Wildfire log entries in your screenshot.

  • 1 accepted solution
  • 4244 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!