---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Block Request Category List

# Block Request Category List {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Block Request Category List classify observables in ServiceNow® based on the block or allow action selected in the CrowdStrike platform. The Category List provides options to initiate a change request for list approval. This ensures that approvals are routed and processed seamlessly as part of the Block Request capability
flow.

## Before you begin

Role required: sn_si.analyst  
Note:  
You must configure the CrowdStrike Falcon Insight configuration tile to use the Block Request Capability for CrowdStrike. For more information on how to configure the integration, see [Install and configure CrowdStrike Falcon Insight](https://servicenow-prod.fluidtopics.net/fNcQz6Ymtsib6osi2_W_IA "Install and configure the CrowdStrike Falcon Insight for Security Operations application from the ServiceNow Store on your ServiceNow AI Platform instance.")

## About this task

The Block Request Category List includes two Hash Categories.

* Allow List Entries -- Displays observables added to the Allow Hash category.
* Block List Entries -- Displays observables added to the Block Hash category.
{#cs-fal-in-block-req-category__ul_c3r_21l_k3c}

## Procedure

1. Navigate to AllCrowdStrike Falcon Insight IntegrationBlock Request Category List.
2. Select Allow Hash.
3. Create a change request:  
   1. Select Create Change Request.
   2. Select and hold (or right-click) the navigation bar and select Save.
   3. A change Request field is created with the Request number.
   {#cs-fal-in-block-req-category__ol_djw_bfj_k3c}
4. Select Approvers:  
   1. Select Require Approval.
   2. Select Approvers for adding observable from the search bar.
   3. Select Approvers for Removing Observable from the search bar.

      For a description of the field values, see [CrowdStrike Block Request Category List](https://servicenow-prod.fluidtopics.net/TTm3z4tmuA8QC5Ulw1467g "Field descriptions for CrowdStrike Block Request Category List form.").
   {#cs-fal-in-block-req-category__ol_jtk_tgj_k3c}
5. Select Update.
{#cs-fal-in-block-req-category__steps_rym_xnd_k3c}

## Result

CrowdStrike Falcon Insight block requests can be reviewed, tracked, and responded to in Security Incident Response using standard Block Request capability flow.

*[\>]: and then


