Observable-level sharing

Prev Next

Specific observables in a feed can be enabled or disabled. Disabling observables can be useful in mitigating false positive verdicts.

The feed details page allows you to enable or disable sharing of individual observables, view observable information and status, and navigate to the appliance details page, where you can view the status of feeds that Helix Enterprise attempted to share with the appliance.

To open the feed details page:
  1. From the main menu, select Manage > Observable Feeds Sharing.

  2. Do one of the following:

    • Click the feed in the Feed Name column.

    • Click the menu in the Options column, and then select View Details.

To enable or disable sharing of specific observables:
  1. Do one of the following:

    • Click the menu in the Options column at the right end of the observable row and select Share Observable.

    • Select one or more checkboxes at the left end of the observable row or rows and click Share Observable at the top right of the table.

  2. Select Enable or Disable, and then click Confirm.