Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Palo Alto Networks integration

Palo Alto Networks integration after configuration enables the threat analysts to add malicious IP addresses, URLs, and domains to External Dynamic List (EDL) or remove these entries from EDL after confirmation as non-malicious or clean.

An EDL is a text file that is hosted on an external web server. For this integration, this web server is your ServiceNow AI Platform instance, which enables the Palo Alto Networks - Firewall to import objects that are included in the list such as IP addresses, URLs, and domains.

  • Create EDL for Palo Alto Networks
    Create External Dynamic List (EDLs) for Palo Alto Networks. After you create EDLs, you can start creating entries for those EDLs.
  • Define Palo Alto Networks Approval Rules
    Activate approval workflows to require approval or rejection of EDL entries before they take effect.
  • Add Observables to EDLs
    Add observables such as IP addresses, domains, and hashes to External Dynamic Lists (EDLs) to automatically update threat intelligence feeds in your security infrastructure.
  • Remove Observables from EDL
    Remove observables from an External Dynamic List (EDL) to stop blocking or monitoring specific observables. Use this when observables are no longer relevant or incorrectly categorized.
  • Approve EDL entries for Palo Alto Networks
    Approving External Dynamic List (EDL) entries is part of the pre configuration. You must approve the EDL entries before the entries are activated on EDLs for the firewall to retrieve the entry and apply the security policy.

Parent Topic:Firewall integration