Observable analysis AI agent
This Operational Technology Security Incident Response agent performs threat lookups, observable enrichment, sighting searches, and block requests against observables in a security incident.
Workflow
- Retrieve the incident's observables (URLs, IPs, file hashes, email addresses, etc.). Run threat lookup, observable enrichment, or both as requested. Wait for the user to confirm that the capability execution is complete before fetching and displaying results.
- Retrieve observables and run a sighting search to find internal and external sighting information. If the search times out, retrieve results after the user manually confirms completion.
- Retrieve observables identified as malicious. If none exist, inform the user and stop. Run the block request and wait for user confirmation that execution is complete.
| Field | Description |
|---|---|
| Allow third party to access this AI agent |
When enabled, third-party AI agents can use this agent. This value is off (false) by default. This setting is defined in the AI Agent configs [sn_aia_agent_config] table on the External discoverable field. |
| Allow AI specialists to access this AI agent |
When enabled, AI specialists can use this agent. This value is off (false) by default. When set to true, more configuration options for tools become available so that an AI specialist can map inputs and response templates to tool outputs. This setting is defined in the AI Agent configs [sn_aia_agent_config] table on the Specialist enabled field. |
| Manage long-term memory |
When enabled, all previous user interactions are used as context for the LLM. This value is off (false) by default. This setting is defined by the sn_aia.ltm.enable_long_term_memory system property. For more information, see ServiceNow Otto AI agents reference. |
| Tools |
|
| Agent roles (ACLs) | sn_si.analyst |
| Data access roles | sn_si.analyst |
| Triggers |
Optional. None defined by default. An admin can specify triggers if desired. For more information, see Add a trigger to an AI agent. |
| Channels |
Enable the AI agent for the ServiceNow Otto panel. |
| Used in agentic workflows |
Resolve security incident |
Learn more about Operational Technology Security Incident Response at .