Submit observables from a security incident record to a URL category list
Submit observables that are attached to a security incident record to a configured URL category list by using the allow or block request. Adding observables to the allow or block list for security scans allows users to review content from these URLs and gain access to trusted content.
Before you begin
Role required: sn_si.analyst
About this task
You submit observable entries by using the allow or block request action from the Associated Observables related list. Observables are artifacts found on a network or operating system that are likely to indicate an intrusion. Use the list of URL Categories configured previously to select the observable that you want to submit. After you submit the request, an approval request is sent to your approval group.