Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

TISC Data Archival

The Threat Intelligence Security Center is provisioned with archival rules in the base system for the TISC table. The related records are also added in the base system to the TISC archive rule.

Before you begin

Role required: admin

Procedure

  1. Navigate to All > System Archiving > Archival Rules.

    The list of archival rules that are applicable for TISC are displayed. These archival rules are different for every object type and are applicable independently.

  2. Filter the tables names starts with sn_sec_tisc.

  3. View the TISC related records.

    Threat Intelligence RecordReference Table
    Archive Attack Patternsn_sec_tisc_attack_pattern
    Archive Campaignsn_sec_tisc_campaign
    Archive Course of Actionsn_sec_tisc_course_of_action
    Archive Data Componentsn_sec_tisc_aggregated_data_component
    Archive Data Sourcesn_sec_tisc_aggregated_data_source
    Archive Identitysn_sec_tisc_identity
    Archive Infrastructuresn_sec_tisc_infrastructure
    Archive Intrusion Setsn_sec_tisc_intrusion_set
    Archive Malwaresn_sec_tisc_malware
    Archive Malware Analysissn_sec_tisc_malware_analysis
    Archive Marking Definitionsn_sec_tisc_marking_definition
    Archive Object Sightingsn_sec_tisc_object_sighting
    Archive Observed Datasn_sec_tisc_observed_data
    Archive Threat Actorsn_sec_tisc_threat_actor
    Archive Threat Eventsn_sec_tisc_threat_event
    Archive Threat Groupingsn_sec_tisc_threat_grouping
    Archive Threat Notesn_sec_tisc_threat_note
    Archive Threat Opinionsn_sec_tisc_threat_opinion
    Archive Threat Reportsn_sec_tisc_threat_report
    Archive Toolsn_sec_tisc_tool
    Archive Vulnerabilitysn_sec_tisc_vulnerability
    Artifactsn_sec_tisc_artifact
    AS Numbersn_sec_tisc_as_number
    Directorysn_sec_tisc_directory
    Email Addresssn_sec_tisc_email_address
    Email Messagesn_sec_tisc_email_message
    Email Subjectsn_sec_tisc_email_subject
    Filesn_sec_tisc_file
    Indicator Archive Rulesn_sec_tisc_indicator
    IPv4 Addresssn_sec_tisc_ipv4_address
    IPv4 CIDRsn_sec_tisc_ipv4_cidr
    IPv6 Addresssn_sec_tisc_ipv6_address
    Locationsn_sec_tisc_location
    MAC Addresssn_sec_tisc_mac_address
    MD5 Hashsn_sec_tisc_md5_hash
    Mutex Namesn_sec_tisc_mutex_name
    Other Observablesn_sec_tisc_other_observable
    Processsn_sec_tisc_process
    SHA1 Hashsn_sec_tisc_sha1_hash
    SHA256 Hashsn_sec_tisc_sha256_hash
    SHA512 Hashsn_sec_tisc_sha512_hash
    URLsn_sec_tisc_url
    User Accountsn_sec_tisc_user_account
    Windows Registry Keysn_sec_tisc_windows_registry_key
    X.509 Certificatesn_sec_tisc_x_509_certificate
    Object-Object Relationship Archive Rulesn_sec_tisc_m2m_object
    Object-Observable Relationship Archive Rulesn_sec_tisc_m2m_object_observable
    Related Indicator Archive Rulesn_sec_tisc_m2m_indicator
    RSS Feed Archive Rulesn_sec_tisc_m2m_object_indicator
    Imports Archive Rulessn_sec_tisc_m2m_indicator_observable

    Note:

    For information on how the archival rules are created, see Create an archive rule in Core UI.

  4. Select an archival rule.

    For example, select Directory observable record to see the base system archival rule.

  5. Update the rule if required.