Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

View Sightings Search Results

You can review Sightings Search Results for internal and external malicious indicators.

Before you begin

Role required: sn_si.analyst

About this task

.

Procedure

  1. Navigate to a security incident.

  2. Select the Sightings Search Results tab from Show IoC Related List group to view the list of sightings searches.

    Note: This data can be shared with Trusted Security Circle.

    ResultDescription
    NumberSightings Search identifier.
    Observable countNumber of observables searched for.
    Internal SightingsAggregated count of internal sightings.
    External SightingsAggregated count of external sightings. (Received from threat sharing.)
    Matched configuration itemsAggregated count of configuration items that matched an existing record in your cmdb.
    Start date rangeTime to start looking for sightings.
    End date rangeTime to stop looking for sightings.
    UpdatedDate and time of last modification.

    To view the details of a single search:

  3. Select a Sightings Search reult in the Sightings Search Results list.

    The Sightings Search Result form displays.

    DetailDescription
    NumberInternal Sightings Search identifier.
    Observable countCount of observables searched for by this query.
    Internal sightingsCount of internal sightings for this search.
    External sightingsCount of external sightings for this search. (Received from Trusted Security Circle.)
    Unmatched hostsList of potential configuration items for this search that were not matched with any records in your cmdb.
    TaskSecurity incident task identifier.
    Start date rangeTime the sightings search started.
    End date rangeTime the sightings search stopped.
    UpdatedDate and time of last modification.
    Sightings Search DetailsType, number of sightings and modification date.
    Matched Configuration ItemsCount of configuration items that matched an existing record in your cmdb. Lists the CI and the Sighting.
    Threat SharesList of the threats shared with Trusted Security Circle.
  4. Share Sightings Search results
    You can share local sightings details or results that are associated with a particular search with your Trusted Security Circle.

  5. Share observables from a security incident
    Observables can be shared from a security incident in Security Incident Response to members in your trusted circle.

Parent Topic:Create sightings search configuration records