If you have many fields that you would like to include in a rule, you can create a list and use the list name in the rule definition. You can add or edit indicators of compromise (IOCs) such as domain names, file hashes, email, and IP addresses. Each list can have a maximum of 28,000 IOCs, and you can have a maximum of 400,000 IOCs. To use more than 28,000 IOCs, you can create multiple lists. If you intend to create a list of IP addresses and use that list against an IP address field (such as srcipv4 or dstipv4), then all of the items in the list need to be IP addresses.
To create an exclusion list:
On the Lists page, click Create List.
Enter a name and optional description.
Select the type of list: Default, Analytics Allowed List, or Intel Matching.
Click Create. The empty list opens and now you must add indicators to it.
Click Add Indicator.
Enter a value, type, risk, and an optional note.
Click Save.
You can also create an exclusion list on the Rules page. At the end of the rule row click More Options
> Edit, and in the rule manager window click Create List.
To edit an existing list, on the Lists page at the end of the list row click More Options
> Edit, and adjust the fields as required.