---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Add Observables to EDLs

# Add Observables to EDLs {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Add observables such as IP addresses, domains, and hashes to External Dynamic Lists (EDLs) to automatically update threat intelligence feeds in your security infrastructure.

## Before you begin

Role required: sn_sec_tisc.analyst

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security Center.
2. Select the Threat Analyst Workbench icon.
3. Navigate to ObservablesAll Observables.
4. Open any observable record.
5. Select Add to EDL button to add the observables to the list.  
   The Add to EDL modal screen appears. Proceed to add observables to the EDLs.
6. **Optional:** Select Remove to remove the observables from the EDLs.  
   For more information, see [Remove Observables from EDL](https://servicenow-prod.fluidtopics.net/vlGULcEQF4LmUkcSufojSw "Remove observables from an External Dynamic List (EDL) to stop blocking or monitoring specific observables. Use this when observables are no longer relevant or incorrectly categorized.").
{#add-obsesrvables-edl__steps_ad1_b3j_z3c}
**Related tasks**   

* [Approve EDL entries for Palo Alto Networks](https://servicenow-prod.fluidtopics.net/lBVr6iA__lOyjmQ~5~yk~w "Approving External Dynamic List (EDL) entries is part of the pre configuration. You must approve the EDL entries before the entries are activated on EDLs for the firewall to retrieve the entry and apply the security policy.")

*[\>]: and then


