Enable AutoFocus Threat Intelligence

With a valid AutoFocus subscription, you can compare the activity on your network with the latest threat data available on the AutoFocus portal. Connecting your firewall and AutoFocus unlocks the following features:
  • Ability to view an AutoFocus intelligence summary for session artifacts recorded in the firewall logs.
  • Ability to open an AutoFocus search for log artifacts from the firewall.
The AutoFocus intelligence summary reveals the prevalence of an artifact on your network and on a global scale. The WildFire verdicts and AutoFocus tags listed for the artifact indicate whether the artifact poses a security risk.
  1. Verify that the AutoFocus license is activated on the firewall.
    1. Select
      Device
      Licenses
      to verify that the AutoFocus Device License is installed and valid (check the expiration date).
    2. If the firewall doesn’t detect the license, see Activate Licenses and Subscriptions.
  2. Connect the firewall to AutoFocus.
    1. Select
      Device
      Setup
      Management
      and edit the AutoFocus settings.
    2. Enter the
      AutoFocus URL
      :
      https://autofocus.paloaltonetworks.com:10443
    3. Use the
      Query Timeout
      field to set the duration of time for the firewall to attempt to query AutoFocus for threat intelligence data. If the AutoFocus portal does not respond before the end of the specified period, the firewall closes the connection.
      As a best practice, set the query timeout to the default value of 15 seconds. AutoFocus queries are optimized to complete within this duration.
    4. Select
      Enabled
      to allow the firewall to connect to AutoFocus.
    5. Click
      OK
      .
    6. Commit
      your changes to retain the AutoFocus settings upon reboot.
  3. Connect AutoFocus to the firewall.
    1. Log in to the AutoFocus portal: https://autofocus.paloaltonetworks.com
    2. Select
      Settings
      .
    3. Add new
      remote systems.
    4. Enter a descriptive
      Name
      to identify the firewall.
    5. Select
      PanOS
      as the System Type.
    6. Enter the firewall IP
      Address
      .
    7. Click
      Save changes
      to add the remote system.
    8. Click
      Save changes
      again on the Settings page to ensure the firewall is successfully added.
  4. Test the connection between the firewall and AutoFocus.
    1. On the firewall, select
      Monitor
      Logs
      Traffic
      .

Related Documentation