---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Invoke Sighting Search from a Security Incident

# Invoke Sighting Search from a Security Incident {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Invoke the sightings search from a SIR security incident by following the below
procedure.

## Before you begin

Role required: ServiceNow AI Platform administrator (sn_si.admin)

## Procedure

1. Navigate to the Security Incidents.
2. Open any existing SIR or create a new SIR.
3. Click Show IoC in Related Links.
4. Click Associated Observables related lists.  
5. Add any existing observables or create new observable.  
6. Select the observables and from Actions on selected rows, click Run Sightings Search.  
7. Ignore the inputs in the next dialog box that asks for time data.  
   There are default values populated. However, the search is performed real time and the time values are ignored for this integration.
8. Check the worknotes for status.  
9. On completion of the search, check the results and details in the related lists.
10. Click on Sightings Search Details tab for details and Sightings Search Results tab for search results.  

