Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Run a sightings search on observables in a case

You can search for observables using the Sighting Search feature to determine how often they occur. Each occurrence is considered a sighting. You can limit the search to the number of sightings within a selected number of days or within a date range.

Before you begin

The Threat Intelligence plugin must be activated to use Security Case Management.

Role required: sn_ti.case_user_write

Procedure

  1. Navigate to All > Threat Intelligence > Case Management > All Cases.

  2. Open the case that contains observables for which you want to run a sightings search.

  3. Click the Case Artifacts related link.

  4. Click the Observables tab.

  5. Select one or more observables for which you want to search for sightings.

Image omitted: run-sightings-search-obs.png
Run a sightings search
  1. From the Actions on selected items drop-down list, select Run sightings search.

    The Run Sighting Search dialog box appears.

Image omitted: SightingsSearch.png
Sightings search
  1. Either enter the number of days or hours you want to search for sightings of the selected observables, or select a date range.

  2. Click Search.

Parent Topic:IoCs and observables in cases

Related topics

Create a case from IoCs or observables

Add IoCs and observables to an existing case

Create an observable from a case