Submit EDL entries from a security incident record for Palo Alto Networks Next-Generation Firewall
Observables attached to a security incident record are submitted for approval as External Dynamic List (EDL) entries to EDLs. An approval process for EDL entries is part of the preconfigured workflow. The firewall imports EDL entries — IP addresses, URLs, domains — that are included in EDL lists and enforces policy.
Antes de Iniciar
Role required: sn_si.analyst for submitting EDL entries. To approve EDL entries: Approval is assigned to sn_si.admin by default, but this authority can be assigned as required by your organization.
Por Que e Quando Desempenhar Esta Tarefa
Users with the sn_si.analyst role submit EDL entries by requesting a block on observables attached to a security incident record. Once submitted, an EDL entry with a status of Pending is generated and sent for approval. The following example shows a block request for a URL observable.
Procedimento
O que Fazer Depois
Approve EDL entries.