Configuration: Wildfire Setting
Focus
Focus
Strata Cloud Manager

Configuration: Wildfire Setting

Table of Contents

Configuration: Wildfire Setting

Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Panorama or Strata Cloud Manager)
  • NGFW, including those funded by Software NGFW Credits
Each of these licenses include access to Strata Cloud Manager:
The other licenses and prerequisites needed for visibility are:
  • A role that has permission to view the dashboard
  • Advanced WildFire (active subscription attached with NGFW and/or Prisma Access)
  • Strata Logging Service
→ The features and capabilities available to you in Strata Cloud Manager depend on which license(s) you are using.
The WildFire configuration settings serve as the basic service management and reporting jump point for the Advanced WildFire cloud-based threat analysis service. These configuration settings provide administrators with centralized visibility through access to the Advanced WildFire reporting through a high-level monitoring dashboard. This dashboard tracks the lifecycle of a sample from its initial submission to the final verdict generation, ensuring that all suspicious activity across the global infrastructure is documented and accessible for forensic review.
From an operational standpoint, you can also manage the Advanced WildFire API tokens. The API management interface allows administrators to generate and manage API tokens, view submission counts, and integrate WildFire’s automated analysis capabilities into custom scripts or third-party security orchestration tools. This programmatic access ensures that files can be submitted and reports retrieved at scale, allowing for seamless integration into a broader security ecosystem beyond standard hardware submissions.
Additionally, you can designate specific regional WildFire clouds—such as those in the US, EU, Singapore, or Japan—to host the secure, virtualized environments where macOS samples are detonated and observed. Advanced WildFire configuration settings allow organizations to satisfy strict regional data residency requirements by controlling the geographic location used for macOS dynamic analysis. This granular governance ensures that while files are temporarily processed in a specific jurisdiction to determine a verdict, they are promptly deleted following analysis, with only the resulting threat intelligence synced back to the primary cloud region. Because this forwarding functionality is disabled by default to maintain a high security baseline, it provides a deliberate mechanism for balancing high-fidelity malware detection with global compliance mandates.
For more details on the Advanced WildFire API tasks and procedures, refer to the: WildFire API Reference
  1. You can access the dedicated Advanced WildFire Dashboard by selecting Dashboard. This automatically redirects you to: Strata Cloud ManagerInsightsAdvanced WildFire.
  2. You can manage your Advanced WildFire APIs from the WildFire Settings. For details on these tasks, refer to:
  3. Enable MacOS (Dynamic Analysis) forwarding support. The file size limits as well as any forwarding profile rules are inherited from the file type MacOSX.
    1. From the WildFire Setting (ConfigurationWildFire Setting), go to the bottom of the page to the Mac OS file forwarding Settings.
    2. Enable Mac OS file forwarding for Dynamic Analysis and select the Preferred Region, whereby suspicious MacOS samples are sent for MacOS dynamic analysis.
      MacOS dynamic analysis forwarding support is available only in select WildFire cloud regions. If your configured WildFire public cloud region does not support MacOS dynamic analysis, the sample is temporarily sent to the region designated for MacOS dynamic analysis, during which the file is analyzed and subsequently deleted. The sample analysis results are then sent to your configured WildFire public cloud region for access.
      The following WildFire public cloud regions are available:
      • United States (US)
      • European Union (EU)
      • Japan (JP)
      • Singapore (SG)
  4. Apply Change to save the configuration.