[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-09-04 UTC."],[[["\u003cp\u003eWildFire integration version 6.0 allows users to connect with Google Security Operations SOAR.\u003c/p\u003e\n"],["\u003cp\u003eTo use the integration, users must obtain their WildFire API key from the WildFire portal under the "My WildFire API Keys" section.\u003c/p\u003e\n"],["\u003cp\u003eThe integration offers actions such as "Detonate File," "Get File," "Get Pcap," "Get Report," and "Ping," with specific parameters and run-on entities.\u003c/p\u003e\n"],["\u003cp\u003e"Detonate File" action enables users to upload a file to WildFire for analysis and report retrieval while other actions are related to files or reports based on filehash.\u003c/p\u003e\n"],["\u003cp\u003eEach action provides Script Results with a "success" flag indicating the outcome, and there is no additional information on Action Results, nor JSON results.\u003c/p\u003e\n"]]],[],null,["# WildFire\n========\n\nIntegration version: 6.0\n\nConfigure WildFire to work with Google Security Operations\n-----------------------------------------------------------\n\nTo obtain the API Key for your WildFire public cloud, please complete following\nsteps:\n\n1. Log in to the [WildFire portal](https://wildfire.paloaltonetworks.com/).\n2. Select **Account** on the navigation bar at the top of the page.\n3. Your API key(s) is under **My WildFire API Keys**.\n\nConfigure WildFire integration in Google SecOps\n-----------------------------------------------\n\nFor detailed instructions on how to configure an integration in\nGoogle SecOps, see [Configure\nintegrations](/chronicle/docs/soar/respond/integrations-setup/configure-integrations).\n\nActions\n-------\n\n### Detonate File\n\n#### Description\n\nUpload a file to WildFire and retrieve a report.\n\n#### Parameters\n\n#### Run On\n\nThis action runs on all entities.\n\n#### Action Results\n\n##### Entity Enrichment\n\nN/A\n\n##### Insights\n\nN/A\n\n##### Script Result\n\n##### JSON Result\n\n N/A\n\n### Get File\n\n#### Description\n\nDownload and save a sample from WildFire.\n\n#### Parameters\n\nN/A\n\n#### Run On\n\nThis action runs on the Filehash entities.\n\n#### Action Results\n\n##### Entity Enrichment\n\nN/A\n\n##### Insights\n\nN/A\n\n##### Script Result\n\n##### JSON Result\n\n N/A\n\n### Get Pcap\n\n#### Description\n\nDownload and save the PCAP file of a sample from WildFire.\n\n#### Parameters\n\nN/A\n\n#### Run On\n\nThis action runs on the Filehash entities.\n\n#### Action Results\n\n##### Entity Enrichment\n\nN/A\n\n##### Insights\n\nN/A\n\n##### Script Result\n\n##### JSON Result\n\n N/A\n\n### Get Report\n\n#### Description\n\nGet a detonation report from WildFire.\n\n#### Parameters\n\nN/A\n\n#### Run On\n\nThis action runs on the Filehash entities.\n\n#### Action Results\n\n##### Entity Enrichment\n\nN/A\n\n##### Insights\n\nN/A\n\n##### Script Result\n\n##### JSON Result\n\n N/A\n\n### Ping\n\n#### Description\n\nTest connectivity to Wildfire.\n\n#### Parameters\n\nN/A\n\n#### Run On\n\nThis action runs on all entities.\n\n#### Action Results\n\n##### Entity Enrichment\n\nN/A\n\n##### Insights\n\nN/A\n\n##### Script Result\n\n##### JSON Result\n\n N/A\n\n**Need more help?** [Get answers from Community members and Google SecOps professionals.](https://security.googlecloudcommunity.com/google-security-operations-2)"]]