Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Activate an EDL manually

If the Palo Alto Networks firewall administrator is not using the ServiceNow AI Platform, and you are directly notified that the Palo Alto Networks Next-Generation Firewall is configured, you can activate the External Dynamic List (EDL) manually.

Before you begin

In Palo Alto Networks, assign an EDL object, policy, and the source URL to the EDL you created. For more information about configuring the EDL to the Palo Alto Networks Next-Generation Firewall in Palo Alto Networks, see Configure an EDL.

Role required: sn_si.admin

About this task

As the ServiceNow AI Platform security incident administrator, you are notified by the Palo Alto Networks firewall administrator when the EDL configuration is complete in the Palo Alto Networks Next-Generation Firewall.

Procedure

  1. Navigate to All > Palo Alto Networks NGFW Integration > Firewall EDL Configuration.

  2. Select the Firewall EDL Configuration module.

  3. In the Palo Alto Networks Firewall External Dynamic Lists list, select an item in the Name column to open it.

  4. On the record that opens, select the Active check box.

  5. Select Update.

    In the Active column of the Palo Alto Networks Firewall External Dynamic Lists list, true is displayed for the state of the EDL.

Result

The EDL is activated and ready to receive EDL entries

What to do next

Submit EDL entries from a security incident or from the blocklist.

  • Configure an EDL
    The Palo Alto Networks firewall administrator configures an EDL to the Palo Alto Networks Next-Generation Firewall once notified the Retrieval URL is available from the ServiceNow AI Platform. Before the EDL can accept EDL entries, it must be configured in Palo Alto Networks, and activated in the ServiceNow AI Platform®.

Parent Topic:Activate an EDL for Palo Alto Networks Next-Generation Firewall