Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Run a Sightings Search

Determine the prevalence of a threat over time or test remediation or eradication efforts. You can select individual or multiple observables and the date range for your search from a security incident. Results are included in the Security Incident Observables related list.

Before you begin

Role required: sn_si.analyst

About this task

The Sightings Search capability has a flow, Security Operations Integration - Sightings Search Flow, that executes the sightings search. This flow accepts a list of observables, finds any implementing capabilities, creates the queries based on Sightings Search Configurations, and executes the searches based on the configured flow.

Note: An active implementation must be configured. Sightings Search supports Elasticsearch, Splunk, McAfee ESM, HPE ArcSight Logger, and QRadar incident enrichment. If no implementations are available, capability actions, such as Run Sightings Search, are not displayed in product menus.

Procedure

  1. Navigate to a security incident.

  2. Select the Show IoC related link.

  3. Select Observables from the Related List tab.

  4. Select the observables you want to perform a sightings search on.

  5. Select Run Sightings Search in the Actions on selected rows... drop-down menu.

    The Run Sightings Search dialog box opens.

    Note: Values entered in the dialog box overwrite capability configuration values for this run.

  6. Choose the number of days or a date range to search for data.

LastThe number of hours or days prior to the creation of the incident to search. The default is 7 days. The limit is 99 hours or days.
betweenRange of dates to search. Default dates are:- The date and time the incident was opened. - The date and time seven days prior to the opening of the incident.
**Note:** **Last** is the number of hours or days prior to the creation of the incident to search. The default is 7 days. The limit is 99 hours or days.
  1. Select Search.

    A Sightings Search record is created. Aggregate and associated sightings data are displayed in the security incident under the Sightings Search Results and Sightings Search Details tabs.

    Note: Sightings search results data can be shared with Trusted Security Circle, with the exception of raw data in the case of implementations configured to include raw data.

    ResultDescription
    NumberThe identifier for the sightings search.
    Observable countNumber of observables searched for by query.
    Internal sightingsCount of internal sightings.
    External sightingsCount of external sightings. (Received from threat sharing.)
    Matched configuration itemsCount of configuration items that matched an existing record in your cmdb for each observable found in your environment.
    Start date rangeTime to start looking for sightings.
    End date rangeTime to stop looking for sightings.
    UpdatedDate and time of the last modification.

    Note: If the implementation used for the sightings search is configured to include raw data, and at least one sighting is found, an attachment containing raw data samples appears at the top of the security incident.

    DetailDescription
    Sighting searchThe identifier for the sightings search.
    ObservableObservable searched for by query.
    Observable typeType of observable searched for by query.
    Internal sightingsAggregated count of internal sightings.
    External sightingsAggregated count of external sightings. (Received from threat sharing.)
    UpdatedDate and time of the last modification.

Parent Topic:Create sightings search configuration records