---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Send observables to EDR

# Send observables to EDR {#ariaid-title1}

* Release version: Yokohama
* 
* Updated April 14, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Send observables to the EDR security tool.

## Before you begin

Role required: sn_sec_tisc.analyst

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security Center.
2. Click the Threat Intel Library icon.
3. Go to ObservablesAll Observables.
4. Open any observable record.
5. Select Send to EDR.  
   The Send to EDR Implementations modal screen is displayed.
6. Select the required implementation from the list.  
   For example, select the implementation associated to Microsoft Defender EDR.
7. Click Next.
8. Select the run time details such as the Title and Description of the implementation.
9. Click Submit.  
   The selected action is executed and an information message is displayed that Observable Send to EDR execution has started and the results of this execution will be available under the Activity Stream after the execution is complete.  
   Note:  
   Once the execution is initiated or completed, a work notes is posted on the activity stream of the form view and you can verify the execution progress accordingly.
{#tisc-ms-defend-edr__steps_tmd_xdc_h1c}

*[\>]: and then


