Observable summary information
The Observables page displays summary information for all ingested observables.
|
Field |
Description |
|---|---|
|
Type |
The type of observable data: |
|
Value |
The data that comprises the observable. |
|
Indicators |
The number of parent indicators containing the observable. |
|
Action |
The action configured for the observable. For more information, refer to Edit Threat Intelligence Director actions at the source, indicator, or observable Level. Indicators can inherit Action settings from a parent source, and observables can inherit Action settings from a parent indicator. For more information, refer to Inheritance in Threat Intelligence Director configurations. |
|
Publish |
The publish setting for the observable. Refer to Pause or publish Threat Intelligence Director data at the source, indicator, or observable Level. Indicators can inherit Publish settings from a parent source, and observables can inherit Publish settings from a parent indicator. For more information, refer to Inheritance in Threat Intelligence Director configurations. |
|
Updated At |
The date and time Threat Intelligence Director last updated the observable. |
|
Expires |
The date that the observable will be automatically purged from Threat Intelligence Director based on TTL for the parent indicator. |
|
Add to Do-Not-Block List button |
Clicking this button adds the observable to the Do Not Block list. Refer to Adding Threat Intelligence Director observables to the Do Not Block list. |