View and manage observables

This task allows you to view all successfully ingested observables and perform management operations such as editing actions, modifying publish settings, and adding observables to the Do Not Block list.

The Observables page displays all successfully ingested observables. Refer to Observable summary information.

Before you begin

Follow these steps to view and manage observables:

Procedure


Step 1

Choose Integrations > + Show more > Threat intelligence director > Sources.

Step 2

Click Observables.

Step 3

View your current observables.

  • To filter the observables displayed on the page, click Filter (filter icon). For more information, refer to Filter Threat Intelligence Director data in table views.

  • If the information in the Value column is cut off, hover over the value.

  • To view indicators that contain the observable, click the number in the Indicators column. The Incidents page opens with the observable value as the filter. For more information, refer to View and manage indicators.

Step 4

Manage your current observables.