Security Operations Integration- Sightings Search capability

  • 릴리스 버전: Australia
  • 업데이트 날짜 2026년 03월 12일
  • 소요 시간: 1분
  • The Sightings Search capability accepts a set of observables, finds any integrations that support a Sightings Search, then executes these searches.

    The Sightings Search capability has a workflow, Security Operations Integration - Sightings Search Flow, that executes the sightings search. This workflow accepts a list of observables, finds any implementing capabilities, creates the queries based on Sightings Search Configurations, and executes the searches based on the configured workflow. Once the search is complete, a note is added to the incident Work notes including whether any sightings were found and if so, how many.

    To view Sightings Search Configurations, navigate to Security Operations > Integrations > Sightings Search Configurations.

    주:
    If no implementations are available, capability actions are not displayed in product menus.