Palo Alto Networks NGFW for Security Operations
Automate block requests with Security Operations Palo Alto Networks NGFW Integration.
Install Trend
View Install Data
| Date | Install Count | Change |
|---|---|---|
| 2026-09-09 | 0 | - |
| 134 days of no change | ||
| 2026-04-27 | 57 | -57 |
| 11 days of no change | ||
| 2026-04-15 | 58 | -1 |
| 8 days of no change | ||
| 2026-04-06 | 59 | -1 |
| 2 days of no change | ||
| 2026-04-03 | 60 | -1 |
| 2026-04-02 | 61 | -1 |
| 31 days of no change | ||
| 2026-03-01 | 62 | -1 |
| 29 days of no change | ||
| 2026-01-30 | 63 | -1 |
| 1 days of no change | ||
| 2026-01-28 | 64 | -1 |
| 3 days of no change | ||
| 2026-01-24 | 65 | -1 |
| 155 days of no change | ||
| 2025-08-21 | 64 | +1 |
| 14 days of no change | ||
| 2025-08-06 | 63 | +1 |
| 40 days of no change | ||
| 2025-06-26 | 62 | +1 |
| 23 days of no change | ||
| 2025-06-02 | 61 | +1 |
| 89 days of no change | ||
| 2025-03-04 | 60 | +1 |
| 8 days of no change | ||
| 2025-02-23 | 59 | +1 |
| 12 days of no change | ||
| 2025-02-10 | 58 | +1 |
About
The Security Operations Palo Alto Networks **®** Next-Generation Firewall (NGFW) integration allows Security Operations Center (SOC) Analysts to block malicious IP addresses, URLs, and domains. The SOC Analyst creates entries for an External Dynamic List (EDL), or _block list, _from observables determined to be malicious on ServiceNow Security Incident Response (SIR) incidents.
Key Features
The main features of the integration include the following:
- Flexibility to create multiple External Dynamic Lists (EDLs) that apply to the different firewall (FW) deny or allow policies. This flexibility enables more detailed reporting on submitted sites. For example, _phishing_, _malware_, and _allow-__listed_ sites.
- Tagging ServiceNow incidents that contain EDL entries by observable type (URL, domain, IP address).
- Configuring EDL expiration periods to maintain EDL list size by automatically expiring or removing older entries.
- Searching for and removing EDL entries or migrating EDL entries between EDL lists.
- Linking EDL entries to observable records and SIR incidents that include threat intelligence results to determine why an IP, URL, or domain is being blocked.