Configure WildFire Portal Settings
Focus
Advanced WildFire Powered by Precision AI™

Configure WildFire Portal Settings

Table of Contents

Configure WildFire Portal Settings

Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
  • Prisma Access (Managed by Panorama)
  • NGFW (Managed by Strata Cloud Manager)
  • NGFW (Managed by PAN-OS or Panorama)
  • VM-Series
  • CN-Series
  • Advanced WildFire License
    For Prisma Access, this is usually included with your Prisma Access license.
This section describes the settings that can be customized for a WildFire cloud account, such as time zone and email notifications for each firewall connected to the account. You can also delete firewall logs stored in the cloud.
The WildFire portal is being deprecated, and verdict notification functionality is moving to Strata Cloud Manager through the WildFire incidents integration with the Unified Incidents Framework. Palo Alto Networks recommends configuring your WildFire notifications in Strata Cloud Manager instead of the portal going forward.
In Strata Cloud Manager, WildFire publishes informational incidents through the Unified Incidents Framework, giving you granular control over which objects (devices, zones, or other managed resources) trigger notifications. Unlike the portal's blanket verdict checkboxes, the SCM integration uses a suppress-by-default model—no incidents are raised until you explicitly create custom settings for specific incident codes and objects. The supported WildFire incident codes correspond to the same verdict types available in the portal:
  • INC_WF_NOTIFICATION_MALWARE
  • INC_WF_NOTIFICATION_PHISHING
  • INC_WF_NOTIFICATION_GRAYWARE
  • INC_WF_NOTIFICATION_BENIGN
If you previously configured notifications in the legacy portal, you must recreate these settings in Strata Cloud Manager because they don't migrate automatically. To prevent duplicate alerts while both systems are active, Strata Cloud Manager sends only one email notification if you configure the same device in both the legacy portal and Strata Cloud Manager.
For complete details on configuring WildFire incident settings in Strata Cloud Manager, see WildFire incidents.
  1. Access the portal settings.
    1. Log in to the WildFire portal.
    2. Select Settings on the menu bar.
  2. Configure the time zone for the WildFire cloud account.
    Select a time zone from the Set Time Zone drop-down and Update Time Zone to save the change.
    The time stamp that appears on WildFire analysis reports is based on the time zone configured for the WildFire cloud account.
  3. (Optional) Delete WildFire logs hosted on the cloud for specific firewalls.
    1. In the Delete WildFire Reports drop-down, select a firewall (by serial number) and Delete Reports to remove logs for that firewall from WildFire portal. This action does not delete logs stored on the firewall.
    2. Click OK to proceed with the deletion.
  4. (Optional) Configure email notifications based on WildFire analysis verdicts.
    The WildFire portal does not send alerts for blocked files that the firewall forwarded for WildFire analysis.
    This functionality is being replaced by WildFire incidents in Strata Cloud Manager, which provides granular per-device and per-object control over verdict notifications through the Unified Incidents Framework. Palo Alto Networks recommends configuring new notification settings in Strata Cloud Manager rather than the portal.
    1. In the Configure Alerts section, select Malware, Phishing, Grayware, and/or Benign check boxes to receive email notifications based on those verdicts:
      • Select the verdict check boxes in the All row to receive verdict notifications for all samples uploaded to the WildFire cloud.
      • Select the verdict check boxes in the Manual row to receive verdict notifications for all samples that are manually uploaded to the WildFire public cloud using the WildFire portal.
      • Select the verdict check boxes for one or several firewall serial numbers to receive verdict notifications for samples submitted by those firewalls.
    2. Select Update Notification to enable verdict notifications to be emailed to the email address associated with your support account.