Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Define observable-observable relationships

Define relationships between observables.

Before you begin

Role required: sn_sec_tisc.analyst

Procedure

  1. Navigate to Workspaces > Threat Intelligence Security Center.

  2. Click on Threat Intel Library icon on the workspace.

  3. Go to Relationships > Observable-Observable.

  4. Click New.

  5. Complete the fields in the form as appropriate.

FieldDescription
Source ObservableSelect and define the source object.
Target ObservableSelect and define the target object.
Relationship TypeA description that provides more details and context about the relationship type. The available options are:Define the relationship direction whether it is direct or inverse. - Inverse - This is the type of relationship between the observable and object. - Direct - This is the type of relationship between the object and observable.
Basis For CorrelationName of the correlation rule based on which the system has identified as the related records of that observable. This rule is auto populated.
  1. Click Submit.

Parent Topic:Relationships Objects