Submit EDL entries from the blocklist for Palo Alto Networks Next-Generation Firewall
For observables determined to be malicious, and not associated with a specific ServiceNow AI Platform security incident, you submit External Dynamic List (EDL) entries from the blocklist.
Before you begin
Role required: sn_si.analyst
About this task
Procedure
-
Navigate to All > Palo Alto Networks NGFW Integration > Firewall EDL Entries.
- Click the Firewall EDL Entries module.
- In the Palo Alto Networks Firewall External Dynamic List Entries list, click New.
-
In the new record that is displayed, in the Entry value
field, enter a value for your observable.
The two possible outcomes of this entry:
- The remaining fields on the form are completed automatically.
- A matching observable is found, and a message is displayed that a matching observable exists. Select the EDL you want to attach this entry to and click Submit. Select the EDL you want to attach this entry to prior to setting the Expiration period.
- A message is displayed that instructs you to complete the form.
- A matching observable has not been found, and you must complete the form. After you complete it, select the EDL you want to attach the observable to and click Submit. An observable record is created.
The following figure shows an example of an existing domain observable and how the fields are completed automatically.
- Click the search icon to select the EDL you want to attach the entry to.
-
Click Submit.
If you have email approval configured in your workflow, an approval email request is sent.
-
If a message is displayed that requests you to fill in the rest of the
information manually, fill in the fields.
Field Description Observable type Observable type that is supported from the dialog. EDL name EDL you want to attach the entry to. Note:Select the EDL want to attach the entry to prior to setting the Expiration period.Enable override (default is selected) Lookup result or source. When configured, permits you to enter a Lookup result and the source used to find the results. These fields are typically populated when a security incident record is created. In this case, there is no lookup result or source, and you fill in these fields in manually. Lookup result Select Unknown or Malicious. Source Source that performs a threat lookup on the EDL entry, for example, ThreatCrowd, etc. Expiration period The expiration period inherited from the EDL by default. You can override this value, but only during the creation of the entry. 0 indicates that the EDL entry never expires.
If you change this value, this entry is active for the number of days you enter. You can enter a minimum value of 1, and there is no maximum value.
For example, if you enter 30 days at 2:01 PM on May 1, the EDL entry will expire at 2:01 PM on May 31.
-
Click Submit.
If you have changed the default expiration period of the EDL entry, a warning confirmation dialog box is displayed indicating that the period differs from the selected EDL.
-
Choose one option to configure the expiration period.
Option Description Yes Confirms your expiration override, saves the record, and returns you to the Palo Alto Networks Firewall External Dynamic List Entries list. If you have email approval configured in your workflow, an approval email request is sent. No Cancels the override. At this point, you can change the value for the Expiration period. After changing the value, click Submit to return to the Palo Alto Networks Firewall External Dynamic List Entries list.
-
If not displayed, navigate to the Palo Alto Networks Firewall
External Dynamic List Entries list and note that the status for
the entry is Pending.
The entry is now ready for approval.