Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Define Observed Data

Conveys information about cyber security related entities such as files, systems, and networks using the STIX Cyber-observable Objects (SCOs).

Before you begin

Role required: sn_sec_tisc.analyst

Procedure

  1. Navigate to Workspaces > Threat Intelligence Security Center.

  2. Click on Threat Intel Library icon on the workspace.

  3. Go to Observed Data object.

  4. Click New.

    Note: Whenever you create new object records for observables, indicators, entities or objects a source record is created and a prompt message is displayed that the new object record is created and then the user is redirected to the aggregated record.

  5. On the form, fill in the fields.

    FieldDescription
    IDUnique ID to identify the observed data.
    First ObservedThe initial time when the data was seen.
    Last observedThe last time when the data was seen.
    Observed CountThe number of times that each Cyber-observable object was seen. The value must be an integer from 1 through 999,999,999.
    TLPTLP is used to ensure that sensitive information is shared with the appropriate audience. It employs four colors (White, Green, Amber, and Red) to indicate different degrees of sensitivity.
    ConfidenceEnter the confidence for the observed data
    SourceSpecifies the threat source from which this object record is created.
    RevokedIndicates that the revoked objects are no longer considered valid by the object creator.
    FieldDescription
    NotesAdd any additional notes for this observed data.
FieldDescription
Additional ContextAdd any additional context for this observed data.
Spec VersionThe version of the STIX specification used to represent this object.The value of this property must be 2.1 for STIX Objects defined according to this specification.
LangThis property identifies the language of the text content in this object.
CreatedSpecifies the date and time when the object is created in the source.
ExtensionsIndicates the extensions of attack pattern.
UpdatedSpecifies the date and time when the object was updated in the source.
Processing StatusRepresents the processing status of this object, course of action.
  1. Click Save.

    After you save, a prompt message is displayed indicating that A new observable record is created. Click Continue to edit the record and create new relationships.

  2. Click Continue.

    Important: After you create a new observable record, Prevent System Updates check box is displayed.

    Select this check box to prevent any updates from the system after the observable or indicator or STIX objects records are created.

    FieldDescription
    Tags
    Select TagsSelect the tags that are associated with the observed data.
    Add TagsAdd new tags.
    Taxonomies
    Select TaxonomySelect a Taxonomy that is associated with this observed data.
    Add Taxonomy ValuesAdd Taxonomy values that are associated with this observed data.

What to do next

Click any of the following related lists to view additional information about objects associated with the observed data.

FieldDescription
External ReferencesLists the external references which refer to non-STIX information. This property is used to provide one or more external object identifiers.
IndicatorsLists the related Indicators of Compromise (IoC) that have been identified by the threat source associated with this object.
InfrastructureLists systems, software services, and any associated physical or virtual resources that are associated with this object.
Marketing DefinitionsLists the marketing definitions associated with this object.
SightingsLists the sightings associated with this object.

Note:

  1. You can link and unlink the related records associated with this object. For more information, see Link Threat Intel Related Records.
  2. The various SDOs within the TI library also contains the potential relationships. To establish a relationships between any two objects, you use the Potential Relationships link from the Threat Intel Library to confirm the relationships between the objects. For more information, see Confirm object-object potential relationships.
  3. Also, use the Related Records section from the objects form view to confirm the relationships between two Objects using the Potential Relationships section available on the form view. For more information on see, Confirm Potential Relationships from Related Records.
  4. You can add objects to cases. For more information, see Add to Case.

Parent Topic:Observed Data