Thank you for your feedback.
Form temporarily unavailable. Please try again or contact to submit your comments.
  • London
  • Kingston
  • Jakarta
  • Istanbul
  • Helsinki
  • Geneva
  • Store

WildFire: get PCAP activity

WildFire: get PCAP activity

The WildFire: Get PCAP workflow activity gets the packet capture (PCAP) information generated during the analysis of a specified file hash on WildFire. The result of this activity is attached to a specific record as identified by the TableName and RecordId.

Input variables

Input variables determine the initial behavior of the activity.

Table 1. Input variables
Variable Description
FileSHA256Hash [string] The hash of the file received from the Palo Alto Network Firewall application.
TableName [string] The affected table.
RecordId [string] The security incident or IoC being updated.

Output variables

The output variables contain data that can be used in subsequent activities.

Table 2. Output variables
Variable Description
commandStatus [Boolean] True if a result is obtained and attached successfully.
errorMessage The error, if any, that occurred in the activity.

This site is scheduled for a small content update on Tuesday, December 18th, between the hours of 4:00pm and 8:00pm Pacific Time (Dec 19 00:00 – Dec 19 4:00 UTC). Access to this site may be slightly delayed during that time.