Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Define observed data

Define observed data that conveys information about cyber security-related entities such as files, systems, and networks using the STIX Cyber-observable Objects (SCOs).

Before you begin

Role required: sn_ti.admin

Procedure

  1. Navigate to All > Threat Intelligence > IoC Repository > Observed Data.

  2. Click New.

  3. Complete the fields in the form as appropriate.

    FieldDescription
    First ObservedThe initial time when the data was seen.
    Last ObservedThe last time when the data was seen.
    Observed CountThe number of times that each Cyber-observable object was seen. The value must be an integer from 1 through 999,999,999.
    SourceSpecifies the threat source from which this record is created.
    Source IDUnique identifier for this object in the threat source.
    Created Time in SourceSpecifies the time the object is created in the source.
    Modified Time in SourceSpecifies the time the object is modified in the source.
  4. Click Submit.

What to do next

Click any of the following related lists to view additional information about objects associated with the observed data.

Related Links and Related ListsDescription
Show RelationshipsOpens the STIX Visualizer where you can view the relationship of the STIX object.Show Relationships appears only when the object has an associated object.
External ReferencesLists external references which refer to non-STIX information. This property is used to provide one or more external object identifiers.
Associated ObservablesLists observables associated with this object.
IndicatorsLists related Indicators of Compromise \(IoC\) that have been identified by the threat source associated with this object.
InfrastructureLists systems, software services, and any associated physical or virtual resources that are associated with this object.

Parent Topic:Observed data