Editing Observable Values Before Approval

ThreatStream enables you to easily edit and resubmit observables that you own. This prevents you from having to specify the correct values in a separate import job.

Note: Only users with the Approve Intel privileges can edit observables for their organization.

Both Included and Excluded observables can be edited. You can only edit pending observables when import jobs are in Ready To Review status.

Editing and Resubmitting Included Observables

To edit Included observables, navigate to the import job that contains the included observables you want to edit and resubmit.

To edit the observable value:

  1. On the Included tab, click the edit icon next to the observable you want to edit.

  2. Edit the value of the observable and click Apply Changes.

To edit the iType mapping, expiration date, or confidence score assigned to the selected observables:

  1. Select the observable of your interest and click Edit.


  2. Make the desired changes to the observable iType, Confidence, or Expiration Date.

    Note: The indicator type of an observable can only be changed to an indicator type of the same type. For example, actor_ip is the indicator type of the IP type, and it can only be changed to another indicator type of the IP type. See Indicator Types in ThreatStream for a complete list of indicator types.

  3. Click Apply Changes.

ThreatStream re-scores the observables based on the changes you made. Updated values are immediately reflected in the import job.

Editing and Resubmitting Excluded Observables

In some cases, observables are Excluded from import jobs due to typos in observable values. ThreatStream enables you to easily edit observable values and resubmit the import job. This prevents you from having to create a separate import job for the excluded observables.

To edit and resubmit excluded observables:

  1. Navigate to the import job that contains the excluded observables you want to resubmit.
  2. Click Excluded.
  3. Click the edit icon corresponding to the observable you want to edit.

  4. Make the desired changes to the observable value or indicator type.

    Note: The indicator type of an observable can only be changed to an indicator type of the same type. For example, actor_ip is the indicator type of the IP type, and it can only be changed to another indicator type of the IP type. SeeIndicator Types in ThreatStream for a complete list of indicator types.

  5. Click Apply Changes.

ThreatStream evaluates the changes you made. The observable is automatically moved to the Included tab if your changes result in a valid observable.