Sighting Search
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
4 hours ago
Give me an overview what is Sighting Search and how to use it. Like i need the navigation to perform this sighting search.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
4 hours ago
Hi @SRIRAMSANKAR007,
Sighting Search checks whether an observable, an IP, domain, or file hash, has actually shown up in your own security tools, like Splunk or QRadar. It tells you if that indicator was really seen in your environment, not just that it's known bad in theory.
Navigation: open the Security Incident, go to the Observables related list, select the observable, then click Run Sighting Search. ServiceNow queries your connected tool through the MID Server and shows matching events on the incident.
Example: an incident has the IP 192.168.168.45 logged as an observable. You select it and run Sighting Search. If Splunk logged any traffic to or from that IP, you get back the timestamps and source, real context instead of just a bad-IP flag.
If nothing comes back, check the integration capability record and MID Server connectivity first. Also scope the query with an index or sourcetype rather than searching everything, a broad search can time out.