<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Intergrations of External Dynamic Lists (EDL) with External Systems in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/intergrations-of-external-dynamic-lists-edl-with-external/m-p/1250840#M6787</link>
    <description>&lt;P&gt;Hi!&amp;nbsp;I’m looking for guidance on whether entries from External Dynamic Lists (EDL) in Palo Alto Networks can be programmatically accessed or integrated with external systems for broader threat intelligence use.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Specifically, I would like to understand:&lt;/P&gt;
&lt;P&gt;Whether EDL contents (IP, domain, URL indicators) can be retrieved via API or another supported method.&lt;/P&gt;
&lt;P&gt;If there is a way to export or query EDL data in near real-time or on a scheduled basis.&lt;/P&gt;
&lt;P&gt;Whether Palo Alto provides any native integrations or mechanisms to share EDL-derived intelligence with external platforms.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Use Cases:&lt;/P&gt;
&lt;P&gt;We are working toward centralizing and reusing threat intelligence across multiple security controls and platforms.&lt;/P&gt;
&lt;P&gt;Some example use cases include:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Azure Integration&lt;/P&gt;
&lt;P&gt;Continuously ingest Tor exit node IPs into an EDL within Palo Alto&lt;/P&gt;
&lt;P&gt;Reuse that same dataset to update Azure controls (Conditional Access, Named Locations, or other access restrictions) to block access to cloud resources from Tor networks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MISP Integration&lt;/P&gt;
&lt;P&gt;Leverage EDL data as a source of indicators for ingestion into MISP&lt;/P&gt;
&lt;P&gt;Enrich or correlate EDL indicators with existing intelligence in MISP&lt;/P&gt;
&lt;P&gt;Use MISP as a central repository while maintaining Palo Alto as an enforcement point&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Additional Questions:&lt;/P&gt;
&lt;P&gt;Are there recommended architectures or best practices for synchronizing EDL-based intelligence with external systems such as Azure or MISP?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are there any limitations or considerations around using EDLs as a source of truth for downstream integrations?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Would Palo Alto recommend an alternative approach (Cortex XSOAR, Cortex XDR, or other integrations) for distributing threat intelligence across multiple environments?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;If direct access to EDL contents is not supported, are there indirect methods (via logs, Cortex Data Lake, or other telemetry) that could be leveraged to operationalize this data externally?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Mar 2026 18:13:35 GMT</pubDate>
    <dc:creator>SarahEubanks</dc:creator>
    <dc:date>2026-03-24T18:13:35Z</dc:date>
    <item>
      <title>Intergrations of External Dynamic Lists (EDL) with External Systems</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/intergrations-of-external-dynamic-lists-edl-with-external/m-p/1250840#M6787</link>
      <description>&lt;P&gt;Hi!&amp;nbsp;I’m looking for guidance on whether entries from External Dynamic Lists (EDL) in Palo Alto Networks can be programmatically accessed or integrated with external systems for broader threat intelligence use.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Specifically, I would like to understand:&lt;/P&gt;
&lt;P&gt;Whether EDL contents (IP, domain, URL indicators) can be retrieved via API or another supported method.&lt;/P&gt;
&lt;P&gt;If there is a way to export or query EDL data in near real-time or on a scheduled basis.&lt;/P&gt;
&lt;P&gt;Whether Palo Alto provides any native integrations or mechanisms to share EDL-derived intelligence with external platforms.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Use Cases:&lt;/P&gt;
&lt;P&gt;We are working toward centralizing and reusing threat intelligence across multiple security controls and platforms.&lt;/P&gt;
&lt;P&gt;Some example use cases include:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Azure Integration&lt;/P&gt;
&lt;P&gt;Continuously ingest Tor exit node IPs into an EDL within Palo Alto&lt;/P&gt;
&lt;P&gt;Reuse that same dataset to update Azure controls (Conditional Access, Named Locations, or other access restrictions) to block access to cloud resources from Tor networks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MISP Integration&lt;/P&gt;
&lt;P&gt;Leverage EDL data as a source of indicators for ingestion into MISP&lt;/P&gt;
&lt;P&gt;Enrich or correlate EDL indicators with existing intelligence in MISP&lt;/P&gt;
&lt;P&gt;Use MISP as a central repository while maintaining Palo Alto as an enforcement point&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Additional Questions:&lt;/P&gt;
&lt;P&gt;Are there recommended architectures or best practices for synchronizing EDL-based intelligence with external systems such as Azure or MISP?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are there any limitations or considerations around using EDLs as a source of truth for downstream integrations?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Would Palo Alto recommend an alternative approach (Cortex XSOAR, Cortex XDR, or other integrations) for distributing threat intelligence across multiple environments?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;If direct access to EDL contents is not supported, are there indirect methods (via logs, Cortex Data Lake, or other telemetry) that could be leveraged to operationalize this data externally?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2026 18:13:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/intergrations-of-external-dynamic-lists-edl-with-external/m-p/1250840#M6787</guid>
      <dc:creator>SarahEubanks</dc:creator>
      <dc:date>2026-03-24T18:13:35Z</dc:date>
    </item>
    <item>
      <title>Re: Intergrations of External Dynamic Lists (EDL) with External Systems</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/intergrations-of-external-dynamic-lists-edl-with-external/m-p/1250885#M6788</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/665143805"&gt;@SarahEubanks&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Whether EDL contents (IP, domain, URL indicators) can be retrieved via API or another supported method?&lt;/STRONG&gt;&amp;nbsp; Yes&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;https://yo.ur.hg.fw/api/?type=op&amp;amp;cmd=&amp;lt;request&amp;gt;&amp;lt;system&amp;gt;&amp;lt;external-list&amp;gt;&amp;lt;show&amp;gt;&amp;lt;type&amp;gt;&amp;lt;predefined-ip&amp;gt;&amp;lt;num-records&amp;gt;10000&amp;lt;/num-records&amp;gt;&amp;lt;name&amp;gt;panw-torexit-ip-list&amp;lt;/name&amp;gt;&amp;lt;/predefined-ip&amp;gt;&amp;lt;/type&amp;gt;&amp;lt;/show&amp;gt;&amp;lt;/external-list&amp;gt;&amp;lt;/system&amp;gt;&amp;lt;/request&amp;gt;&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here are a few notes:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Without the num-records parameter, the default number is 100.&amp;nbsp;&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HAuUCAW" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HAuUCAW&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;You can use the API browser to find the XPath for other types of EDLs.&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/ngfw/api/getting-started/explore-xmlapi/explore-browser" target="_blank"&gt;https://docs.paloaltonetworks.com/ngfw/api/getting-started/explore-xmlapi/explore-browser&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;My NGFW did not list the names of the predefined EDLs on the XML API Browser.&amp;nbsp; It is important to know that the XML API Browser mirrors the CLI.&amp;nbsp; I found the names on the CLI and inserted it into the query above.&amp;nbsp; See the output below.&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI-CODE lang="markup"&gt;myname@myngfw(active)&amp;gt; request system external-list show type predefined-ip name 
  panw-bulletproof-ip-list   panw-bulletproof-ip-list
  panw-highrisk-ip-list      panw-highrisk-ip-list
  panw-known-ip-list         panw-known-ip-list
  panw-torexit-ip-list       panw-torexit-ip-list
  &amp;lt;name&amp;gt;                     &amp;lt;name&amp;gt;&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;If there is a way to export or query EDL data in near real-time or on a scheduled basis?&lt;/STRONG&gt;&amp;nbsp; Yes.&amp;nbsp; The API query on the largest predefined IP list took about 1 second.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Whether Palo Alto provides any native integrations or mechanisms to share EDL-derived intelligence with external platforms?&amp;nbsp;&lt;/STRONG&gt; I don't think there are integrations native to PAN-OS.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Would Palo Alto recommend an alternative approach (Cortex XSOAR, Cortex XDR, or other integrations) for distributing threat intelligence across multiple environments?&lt;/STRONG&gt;&amp;nbsp; I'm sure they would recommend Cortex XSOAR.&amp;nbsp; It has a LOT more features and includes the predefined EDLs.&amp;nbsp;&amp;nbsp;&lt;A href="https://xsoar.pan.dev/docs/reference/index" target="_blank"&gt;https://xsoar.pan.dev/docs/reference/index&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp; (Search for "predefined edl").&amp;nbsp; You may need the TIM (Threat Intelligence Management) license.&amp;nbsp; I am not sure.&amp;nbsp;&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-SaaS-Documentation/Understand-Cortex-XSOAR-licenses?tocId=0ww116~l5HOISr58cfY75g" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-SaaS-Documentation/Understand-Cortex-XSOAR-licenses?tocId=0ww116~l5HOISr58cfY75g&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Are there any limitations or considerations around using EDLs as a source of truth for downstream integrations?&lt;/STRONG&gt;&amp;nbsp; Not that I know.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Are there recommended architectures or best practices for synchronizing EDL-based intelligence with external systems such as Azure or MISP?&lt;/STRONG&gt;&amp;nbsp; There are best practice guides for Cortex XSOAR.&amp;nbsp; With regard to automation, there are a million ways to do it.&amp;nbsp; It sounds like you are starting at a good place and will grow from there.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Tom&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2026 02:12:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/intergrations-of-external-dynamic-lists-edl-with-external/m-p/1250885#M6788</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2026-03-25T02:12:22Z</dc:date>
    </item>
  </channel>
</rss>

