Review the aggregate details of all sighting searches.
Before you begin
Role required: sn_si.analyst
Procedure
-
Navigate to a security incident.
-
Select the Sightings Search Details tab from
Show IoC Related List group to view the list of
sightings searches.
Note: This data can be shared with Trusted Security Circle.
Table 1. Sightings Search Details
| Detail |
Description |
| Observable |
List of all observables searched for by query. |
| Observable type |
|
| Internal sightings |
Count of internal sightings for all searches. |
| External sightings |
Count of external sightings for all searches. (Received
from threat sharing.) |
| Sighting search |
Sightings Search identifier. |
| Updated |
Date and time of last modification. |