---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Remove Observables from EDL

# Remove Observables from EDL {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Remove observables from an External Dynamic List (EDL) to stop blocking or monitoring specific observables. Use this when observables are no longer relevant or incorrectly categorized.

## Before you begin

Role required: sn_sec_tisc.analyst

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security Center.
2. Select the Threat Analyst Workbench.
3. Navigate to ObservablesAll Observables.
4. Open any observable record.
5. Select Remove from EDL button to remove the entries from the list.  
   The Remove from EDL modal opens. Complete the removal process. You can add observables back to the list later. For more information, see [Add Observables to EDLs](https://servicenow-prod.fluidtopics.net/8HgG1~ts__zwYTPFkIXoMA "Add observables such as IP addresses, domains, and hashes to External Dynamic Lists (EDLs) to automatically update threat intelligence feeds in your security infrastructure.").
{#remove-observables-edl__steps_xxt_rks_2dc}
**Related tasks**   

* [Approve EDL entries for Palo Alto Networks](https://servicenow-prod.fluidtopics.net/lBVr6iA__lOyjmQ~5~yk~w "Approving External Dynamic List (EDL) entries is part of the pre configuration. You must approve the EDL entries before the entries are activated on EDLs for the firewall to retrieve the entry and apply the security policy.")

*[\>]: and then


