This task allows you to view all successfully ingested observables and perform management operations such as editing actions, modifying publish settings, and adding observables to the Do Not Block list.
The Observables page displays all successfully ingested observables. Refer to Observable summary information.
Before you begin
Follow these steps to view and manage observables:
Procedure
Step 1 | Choose . |
Step 2 | Click Observables. |
Step 3 | View your current observables.
-
To filter the observables displayed on the page, click Filter ( ). For more information, refer to Filter Threat Intelligence Director data in table views.
-
If the information in the Value column is cut off, hover over the value.
-
To view indicators that contain the observable, click the number in the Indicators column. The Incidents page opens with the observable value as the filter. For more information, refer to View and manage indicators.
|
Step 4 | Manage your current observables.
-
To edit the Action, refer to Edit Threat Intelligence Director actions at the source, indicator, or observable Level.
-
To edit the Publish setting for an observable, refer to Pause or publish Threat Intelligence Director data at the source, indicator, or observable Level.
-
To change the expiration date for an observable, modify the TTL for the parent source. For more information, refer to View and manage sources.
-
To add an observable to the Do Not Block list, click the Add to Do-Not-Block List button. For more information, refer to Adding Threat Intelligence Director observables to the Do Not Block list.
|