Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

View Sightings Search Data

Review the aggregate data of all sighting searches.

Before you begin

Role required: sn_si.analyst

Procedure

  1. Navigate to a security incident.

  2. Select the Sightings Search Data tab from Show All Related Lists Related List group to view the list of sightings searches.

    Note: This data can be shared with Trusted Security Circle.

ResultDescription
End date rangeTime to stop looking for sightings.
External SightingsAggregated count of external sightings. \(Received from threat sharing.\)
Internal SightingsAggregated count of internal sightings.
Is LocalIndicates whether the sightings came from the current or a shared environment.
ObservableList of all observables searched for by query.
Sighting countNumber of sightings searched for.
Sighting searchSightings Search identifier.
Sighting search detailAggregate detail of the sighting search.
Sighting search linkLink pointing to the Sighting search portal. The search query is automatically applied upon clicking the Sighting search link.
Sighting search query

Query to identify the instance. 172.10.0.171 is substitutable and gets substituted in the observable selected.

(search 172.10.0.171 \| head 10)

Note: Selection of days will not be applicable to Saved search.

Parent Topic:Create sightings search configuration records