---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Palo Alto Networks integration

# Palo Alto Networks integration {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

Palo Alto Networks integration once configured enables the threat analyst to add malicious IP addresses, URLs, and domains to External Dynamic List (EDL) or remove these entries from EDL once confirmed as non-malicious or
clean.

An EDL is a text file that is hosted on an external web server. For this integration, this web server is your ServiceNow AI Platform instance, which permits the Palo Alto Networks Firewall to import objects that are included in the list, IP
addresses, URLs, and domains.
* **[Create new EDL for Palo Alto Networks](https://servicenow-prod.fluidtopics.net/CWC4OQtuS1f6ea~f_z6Xmw)**   
  Create new External Dynamic List (EDLs) for Palo Alto Networks. Once you create EDLs, you can start creating entries for those EDLs.
* **[Palo Alto EDL Approval Rules](https://servicenow-prod.fluidtopics.net/itjO19nFbHbBBt3FXmkPZw)**   
  Approval rules allows the users to activate the approval work flow required to approve or reject the EDL entries.
* **[Add Observables to EDL](https://servicenow-prod.fluidtopics.net/6g6Fqaz3O2~qRSUG0jCYIg)**   
  Add observables such as IPs, domains, and hashes to External Dynamic List (EDLs).
* **[Remove Observables from EDL](https://servicenow-prod.fluidtopics.net/7kM079oWhuahbrOo~vb5mQ)**   
  Remove observables from EDL.
* **[Approve EDL entries for Palo Alto Networks](https://servicenow-prod.fluidtopics.net/5lsT7VkVtgLssXc4FVXIfw)**   
  Approving External Dynamic List (EDL) entries is part of the pre configuration. You must approve the EDL entries before the entries are activated on EDLs for the firewall to retrieve the entry and apply the security policy.

