Remove Observables from EDL
Remove observables from an External Dynamic List (EDL) to stop blocking or monitoring specific observables. Use this when observables are no longer relevant or incorrectly categorized.
Before you begin
Role required: sn_sec_tisc.analyst
Procedure
Navigate to Workspaces > Threat Intelligence Security Center.
Select the Threat Analyst Workbench.
Navigate to Observables > All Observables.
Open any observable record.
Select Remove from EDL button to remove the entries from the list.
The Remove from EDL modal opens. Complete the removal process. You can add observables back to the list later. For more information, see Add Observables to EDLs.
Parent Topic:Palo Alto Networks integration
Related topics