---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Submit EDL entries from a security incident record for Palo Alto Networks Next-Generation Firewall

# Submit EDL entries from a security incident record for Palo Alto Networks Next-Generation Firewall {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 min. de leitura

Observables attached to a security incident record are submitted for approval as
External Dynamic List (EDL) entries to EDLs. An approval process for EDL entries is part of
the preconfigured workflow. The firewall imports EDL entries --- IP addresses, URLs, domains ---
that are included in EDL lists and enforces policy.

## Antes de Iniciar

Role required: sn_si.analyst for submitting EDL entries. To approve EDL entries:
Approval is assigned to sn_si.admin by default, but this authority can be assigned
as required by your organization.

## Por Que e Quando Desempenhar Esta Tarefa

Users with the sn_si.analyst role submit EDL entries by requesting a block on
observables attached to a security incident record. Once submitted, an EDL entry
with a status of Pending is generated and sent for approval. The following example
shows a block request for a URL observable.

## Procedimento

1. Navigate to AllSecurity IncidentIncidentsShow All Incidents, and click a security incident record to open it.
2. Click the Show IoC related link.  
3. In the Observables related list, select the observables you want to block and from the Actions on selected rows list, select Block Request.  
4. In the dialog box that is displayed, click the search icon (![Search icon]()).
5. From the list that is displayed, select the EDL you want to attach this entry to.  
   Nota:  
   For this example, the entry observable type (URL) should match the EDL observable type (URL).
6. In the Block Request dialog box with the EDL name displayed in the Implementation field, click Block.  
7. Navigate to Palo Alto Networks NGFW IntegrationFirewall EDL Entries and click Firewall EDL Entries.  
8. In the Palo Alto Networks Firewall External Dynamic List Entries list, click your observable in the Entry value column to open the record.  
   For this example, the record for mail.dgtnetworks.com
   is displayed.

   The status is Pending, the Active check box is cleared, and the work notes
   show that there is a request to add the observable. This EDL Entry request
   is ready for approval.

   The Entry value and Observable fields show different formats for the URL
   observable.

   The icon next to the Observable field is a link
   to the ServiceNow AI Platform®
   Observable table.

   The value in the Observable field
   (http://mail.dgtnetworks.com) links to the
   Observable table, and it matches the format that was brought over from the
   Security Incident Response incident-triggering event.

   The ServiceNow AI Platform®
   may automatically modify EDL entries so that they are compatible with the
   Palo Alto Networks
   EDL URL format.

   In this example, the observable was created with the http:// protocol
   (http://mail.dgtnetworks.com), and this
   format is displayed in the Observable field. The http:// protocol is
   stripped off automatically from the observable by the ServiceNow AI Platform® so
   it is compatible with Palo Alto Networks and
   can be retrieved. As a result,
   mail.dgtnetworks.com is displayed in the
   Entry value field.

## O que Fazer Depois

Approve EDL entries.
**Tópico anterior:** [Activate an EDL for Palo Alto Networks Next-Generation Firewall with a change request](https://servicenow-prod.fluidtopics.net/62fDYndCL~YSTIa1lgXqCg "If configured, the ServiceNow change request form is used to activate the External Dynamic List (EDL). This option is recommended if your firewall administrator is also using the ServiceNow AI Platform for firewall policy or rule changes. The EDL is activated automatically and ready to receive EDL entries upon closure of the ServiceNow AI Platform change request.")  
**Próximo tópico:** [Submit EDL entries from the blocklist for Palo Alto Networks Next-Generation Firewall](https://servicenow-prod.fluidtopics.net/EATalnku~Af4ZWORT9zQZg "For observables determined to be malicious, and not associated with a specific ServiceNow AI Platform security incident, you submit External Dynamic List (EDL) entries from the blocklist.")  
**Referência relacionada**   

* [EDL entry exceptions for Palo Alto Networks Next-Generation Firewall](https://servicenow-prod.fluidtopics.net/mI78e66eKCX1dBnnADmN2g "There are restrictions for adding External Dynamic List (EDL) entries to EDLs. If duplicate, compatibility, or CIDR (Classless Inter-Domain Routing) conflicts exist when you try to add EDL entries to EDLs, error messages are displayed that help you resolve these errors.")

