Add Observables to EDLs
Add observables such as IP addresses, domains, and hashes to External Dynamic Lists (EDLs) to automatically update threat intelligence feeds in your security infrastructure.
Before you begin
Role required: sn_sec_tisc.analyst
Procedure
Navigate to Workspaces > Threat Intelligence Security Center.
Select the Threat Analyst Workbench icon.
Navigate to Observables > All Observables.
Open any observable record.
Select Add to EDL button to add the observables to the list.
The Add to EDL modal screen appears. Proceed to add observables to the EDLs.
Select Remove to remove the observables from the EDLs.
For more information, see Remove Observables from EDL.
Parent Topic:Palo Alto Networks integration
Related topics