You can share local sightings details or results that are associated with a
particular search with your Trusted Security Circle.
Before you begin
Role required: sn_si.analyst
About this task
Sharing can be automated using the following Security Incident Response
Properties.
- Automatically share the results of a sightings search to the default ServiceNow
trusted circle
- Include observables with no local sightings when automatically sharing sightings
search results
- Respond with local sightings whenever a threat share is received from a trusted
circle
Procedure
-
Navigate to a security incident.
-
Click the Show IoC related list and select the
Sightings Search Results tab to view the list of
sightings searches.
-
Click on a sightings search result.
-
On the Sightings Search Resultform, click the
Share sighting search result related link.
The Sighting Search Result Share dialog box appears.
-
Enter a Name for this observable share record.
-
Enter a Descriptionof the observables to share.
-
Choose Circles to share the observables with.
-
Click Submit.
The observable(s) are shared with the specified Trusted Circle.