Use PDIs? Take our 5-minute survey to help shape the PDI roadmap.

Sighting Search

SRIRAMSANKAR007
Tera Contributor

Give me an overview what is Sighting Search and how to use it. Like i need the navigation to perform this sighting search.

1 REPLY 1

rahulswami
Giga Contributor

Hi @SRIRAMSANKAR007,

Sighting Search checks whether an observable, an IP, domain, or file hash, has actually shown up in your own security tools, like Splunk or QRadar. It tells you if that indicator was really seen in your environment, not just that it's known bad in theory.

Navigation: open the Security Incident, go to the Observables related list, select the observable, then click Run Sighting Search. ServiceNow queries your connected tool through the MID Server and shows matching events on the incident.

Example: an incident has the IP 192.168.168.45 logged as an observable. You select it and run Sighting Search. If Splunk logged any traffic to or from that IP, you get back the timestamps and source, real context instead of just a bad-IP flag.

If nothing comes back, check the integration capability record and MID Server connectivity first. Also scope the query with an index or sourcetype rather than searching everything, a broad search can time out.