WildFire Cloud Artifacts

AutoFocus™ receives sample and session information from WildFire™ clouds. Now, sample and session information in AutoFocus includes the WildFire cloud to which a sample was submitted for analysis.
  • Find samples submitted to a specific WildFire cloud.
    1. Start an AutoFocus search with the sample artifact type
      Region
      .
      region-sample.png
    2. Select a WildFire cloud, and click
      Search
      .
    3. Click on a sample hash, and verify that the Region associated with the sample matches your selection.
      region-sample-eu-us.png
      It’s possible for different users to forward the same sample to more than one WildFire cloud; in this case, the Region information for the sample lists all WildFire clouds that received the sample.
      To find samples that have been submitted to only a single WildFire cloud (and no other WildFire clouds), set up a search for a WildFire cloud. Then, add another search condition excluding samples submitted to the other clouds from the search results. For example, to search for samples that users submitted to the WildFire global cloud only, search with the condition
      Region
      is
      US
      combined with the condition
      Region
      is not
      for each of the other WildFire clouds.
  • Find sessions associated with a specific WildFire cloud.
    1. Start an AutoFocus search with the session artifact type Region.
      region-session.png
    2. Select a WildFire cloud, and click
      Search
      .
    3. Click
      Sessions
      to view session search results.
    4. Click on a session time stamp to view sessions details, and verify that the Region listed for the session matches your selection. A session can only be associated with a single WildFire cloud.
      region-session-us-1.png

Recommended For You