1. Palo Alto Networks. (2023). Enterprise DLP Datasheet. "Palo Alto Networks Enterprise DLP is a cloud-delivered service that helps you discover, monitor, and protect sensitive data across your enterprise... When the firewall detects traffic that matches a Data Filtering profile, it forwards the content to the Enterprise DLP cloud service for analysis." (Page 1, "How It Works" section).
2. Palo Alto Networks. (2023). PAN-OS® 11.0 Administrator's Guide. In the "Data Filtering" chapter, under the "Data Filtering Overview" section, it states: "When you activate the Enterprise DLP plugin, the firewall uses the DLP cloud service to check for sensitive data in web (HTTP/HTTPS), FTP, and email (SMTP/IMAP) traffic." This confirms the use of a cloud service for data analysis based on Data Filtering profiles.
3. Palo Alto Networks. (2023). PAN-OS® 11.0 Administrator's Guide. In the "WildFire" chapter, under the "WildFire Overview" section, it clarifies its function: "WildFire® is a cloud-based service that provides advanced threat analysis for unknown files..." This explicitly differentiates it from the non-file-based analysis described in the question.