Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Invoke Sighting Search from a Security Incident

Invoke the sightings search from a SIR security incident by following the below procedure.

Before you begin

Role required: ServiceNow AI Platform administrator (sn_si.admin)

Procedure

  1. Navigate to the Security Incidents.

  2. Open any existing SIR or create a new SIR.

  3. Click Show IoC in Related Links.

  4. Click Associated Observables related lists.

Image omitted: invoke-sighting-search-from-security-incident.png
Associated Observables related list selected
  1. Add any existing observables or create new observable.
Image omitted: invoke-sighting-search-create-observable.png
Add a new or existing Associated Observable to the related list
  1. Select the observables and from Actions on selected rows, click Run Sightings Search.
Image omitted: invoke-sighting-search-run-sighting-search.png
Observables in the list selected and Run Sightings Search selected
  1. Ignore the inputs in the next dialog box that asks for time data.

    There are default values populated. However, the search is performed real time and the time values are ignored for this integration.

Image omitted: run-sightings-search.png
Run Sightings search
  1. Check the worknotes for status.
Image omitted: invoke-status-worknotes.png
Security Incident work notes
  1. On completion of the search, check the results and details in the related lists.

  2. Click on Sightings Search Details tab for details and Sightings Search Results tab for search results.

Image omitted: invoke-sightings-search-details-tab.png
Sighting Search Details
Image omitted: invoke-sightings-search-results.png
Sightings Search Results