---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Get WildFire Data Enrichment Flow

# Get WildFire Data Enrichment Flow {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

When the Security Operations Palo Alto Networks - Get WildFire Data Enrichment flow is executed, a hash file is uploaded to WildFire. The data is enriched, and reports are downloaded to the instance to
aid in processing potential malware attacks.

## Before you begin

Role required: sn_si.analyst

## About this task

The Security Operations Palo Alto Networks - Get WildFire Data Enrichment flow is executed when a security incident is created from an alert received from the Palo Alto Network Firewall application. A
malware hash from the email notification received from Firewall is entered on the IoC tab of the security incident, and the record is updated.

## Procedure

1. Navigate to AllSecurity IncidentShow Open Incidents.
2. Based on the email notification received from Firewall, locate and open the security incident that was created.
3. Select the Indicators of Compromise tab and populate the Malware hash with the hash you received in the alert.
4. Select Update.  
   The flow causes the hash file to be uploaded to WildFire where the data is enriched. Reports in the PDF and XML formats are attached to the record (security incident or IoC) in your instance to aid in processing potential malware attacks.  
   Note:  
   If the enriched data includes packet capture information, PCAP information is also downloaded. PCAP data captures what actions the file was performing. For example, it can report on what servers the file was contacting. To view PCAP files, you need a packet analyzer, such as [Wireshark](https://www.wireshark.org/).
   Figure 1. Sample PDF generated by Wildfire

## WildFire- get PCAP action {#ariaid-title2}

The WildFire: Get PCAP flow action gets the packet capture (PCAP) information generated during the analysis of a specified file hash on WildFire. The result of this action is attached to a specific
record as identified by the TableName and RecordId.

### Input variables

Input variables determine the initial behavior of the action.
{#pan-wildfire-get-pcap__table_pgm_tfy_jr__entry__2}

| Variable | Description |
|-|-|
| FileSHA256Hash \[string\] | The hash of the file received from the Palo Alto Network Firewall application. |
| TableName \[string\] | The affected table. |
| RecordId \[string\] | The security incident or IoC being updated. |
[Table 1. Input variables]

{#pan-wildfire-get-pcap__table_pgm_tfy_jr}

### Output variables

The output variables contain data that can be used in subsequent actions.
{#pan-wildfire-get-pcap__table_bnj_jfy_jr__entry__2}

| Variable | Description |
|-|-|
| commandStatus \[Boolean\] | True if a result is obtained and attached successfully. |
| errorMessage | The error, if any, that occurred in the action. |
[Table 2. Output variables]

{#pan-wildfire-get-pcap__table_bnj_jfy_jr}

## WildFire- get PDF report action {#ariaid-title3}

The WildFire: Get PDF Report flow action gets the report generated during the analysis of a specified file hash on WildFire in PDF format. The result of this action is attached to a specific record as
identified by the TableName and RecordId.

### Input variables

Input variables determine the initial behavior of the action.
{#pan-get-pdf-report-activity__table_pgm_tfy_jr__entry__2}

| Variable | Description |
|-|-|
| TableName \[string\] | The affected table. |
| FileSHA256Hash \[string\] | The hash of the file received from the Palo Alto Network Firewall application. |
| RecordId \[string\] | The security incident or IoC being updated. |
[Table 3. Input variables]

{#pan-get-pdf-report-activity__table_pgm_tfy_jr}

### Output variables

The output variables contain data that can be used in subsequent actions.
{#pan-get-pdf-report-activity__table_bnj_jfy_jr__entry__2}

| Variable | Description |
|-|-|
| commandStatus \[Boolean\] | True if a result is obtained and attached successfully. |
| errorMessage | The error, if any, that occurred in the action. |
[Table 4. Output variables]

{#pan-get-pdf-report-activity__table_bnj_jfy_jr}

## WildFire- get XML report action {#ariaid-title4}

The WildFire: Get XML Report flow action gets the report generated during the analysis of a specified file hash on WildFire in XML format. The result of this action is attached to a specific record as
identified by the TableName and RecordId.

### Input variables

Input variables determine the initial behavior of the action.
{#pan-get-xml-report-activity__table_pgm_tfy_jr__entry__2}

| Variable | Description |
|-|-|
| TableName \[string\] | The affected table. |
| FileSHA256Hash \[string\] | The hash of the file received from the Palo Alto Network Firewall application. |
| RecordId \[string\] | The security incident or IoC being updated. |
[Table 5. Input variables]

{#pan-get-xml-report-activity__table_pgm_tfy_jr}

### Output variables

The output variables contain data that can be used in subsequent actions.
{#pan-get-xml-report-activity__table_bnj_jfy_jr__entry__2}

| Variable | Description |
|-|-|
| commandStatus \[Boolean\] | True if a result is obtained and attached successfully. |
| errorMessage | The error, if any, that occurred in the action. |
[Table 6. Output variables]

{#pan-get-xml-report-activity__table_bnj_jfy_jr}

*[\>]: and then


