Use this feature to add or remove observables in bulk.
Before you begin
Role required: sn_sec_tisc.admin
Procedure
-
Navigate to .
-
Go to .
For example, adding observables to allow list then go to Allow list option.
-
Select Allow List.
-
Select the Observables type such as IP Address, File and so on to add to the allow list.
-
Click Add.
The Select Observables For Allow list is displayed.
-
Select all those observables that are required to be added to the allow list.
-
Click Add to Allow List.
The selected observables are added.
-
Similarly, select Add to Deny list to add the observables to the removed list.
-
Select Add to Watch list to add the observables to the watch list.
Note: You can directly add the observables to allow list, deny list, or watch list directly from the Observables form view page, which are available above the form banner.
-
To verify, navigate to Threat Intel Library.
-
Select the observable type that was added to the allow list.
The observable is indicated as added to allow list.
Note: Allow list and deny list are mutually exclusive and the system will automatically ensure that an observable in allow list is not part of deny list and
vice-versa.