logo

NJP

Palo Alto Networks NGFW for Security Operations

Palo Alto Networks NGFW for Security Operations

by Service-now.com

Automate block requests with Security Operations Palo Alto Networks NGFW Integration.

0 installs 0 reviews v10.5.3 Scoped Application Free (integration tables[3] not counted) 3 tables
Developer Instance Sub-Production

Install Trend

First tracked: 2024-10-30 Latest: 2026-09-09 (0 installs)
View Install Data
Date Install Count Change
2026-09-09 0 -
134 days of no change
2026-04-27 57 -57
11 days of no change
2026-04-15 58 -1
8 days of no change
2026-04-06 59 -1
2 days of no change
2026-04-03 60 -1
2026-04-02 61 -1
31 days of no change
2026-03-01 62 -1
29 days of no change
2026-01-30 63 -1
1 days of no change
2026-01-28 64 -1
3 days of no change
2026-01-24 65 -1
155 days of no change
2025-08-21 64 +1
14 days of no change
2025-08-06 63 +1
40 days of no change
2025-06-26 62 +1
23 days of no change
2025-06-02 61 +1
89 days of no change
2025-03-04 60 +1
8 days of no change
2025-02-23 59 +1
12 days of no change
2025-02-10 58 +1

About

The Security Operations Palo Alto Networks **®**  Next-Generation Firewall (NGFW) integration allows Security Operations Center (SOC) Analysts to block malicious IP addresses, URLs, and domains. The SOC Analyst creates entries for an External Dynamic List (EDL), or _block list, _from observables determined to be malicious on ServiceNow Security Incident Response (SIR) incidents.   

Key Features

The main features of the integration include the following:

- Flexibility to create multiple External Dynamic Lists (EDLs) that apply to the different firewall (FW) deny or allow policies. This flexibility enables more detailed reporting on submitted sites. For example, _phishing_, _malware_, and _allow-__listed_ sites.
- Tagging ServiceNow incidents that contain EDL entries by observable type (URL, domain, IP address).
- Configuring EDL expiration periods to maintain EDL list size by automatically expiring or removing older entries.
- Searching for and removing EDL entries or migrating EDL entries between EDL lists.
- Linking EDL entries to observable records and SIR incidents that include threat intelligence results to determine why an IP, URL, or domain is being blocked. 

Version History (4)
v10.5.3 2026-06-16 16:44:30
Fixed: IPv6 CIDR conflict detection.
v10.5.2 2025-12-11 13:43:29
New : Upgraded all dictionary-level read-only fields to Strict Read-Only to enhance security and prevent unauthorized changes.This update ensures ...
v10.4.7 2025-05-01 18:55:46
Fixed: Pop-up loop when creating EDL Entry with different Expiration Date than default.
v10.4.6 2024-11-07 15:06:22
Changed: Migration of Workflows to Flow Designer flows.
ID: 031a46fb87401300bbc71c7df7cb0b23 · Published: Jun 2026 · Updated: Sep 09, 2026