WildFire Submission [Logs] verdict is "malicious" and traffic is "allowed", while configured action is "blocked"

I have configured the Anti-Virus security profile action as "blocked/sinkhole" if the verdict is "malicious". Still, the WildFire submission report indicates a "malicious" entity was "allowed'.

Environment

Answer

  1. WildFire can't block if the submissions are Elink.
  1. If the file type is "LNK File", the traffic can't be blocked by the firewall.
  2. The file is unknown to WildFire.
  3. Age-out or stale signatures
  4. Old Anti-Virus package or WildFire package is not timely updated
  5. Configuration issue:
  6. CTD inspection queue is full:
  7. File size:

Additional Information