Configure MISP sighting searches
Configure the ServiceNow AI Platform to do sighting searches for observables in the MISP instance. With this information, you can determine how often threats occur.
Before you begin
- Review the MISP user role and permissions that are required for using the MISP bi-directional features.
- Role required: sn_si.admin, sn_ti.admin
About this task
The Security Operations Integration - Sightings Search workflow executes the sighting searches. This workflow accepts a list of observables, finds any implementing capabilities, creates the queries that are based on the sighting search configurations, and executes the searches that are based on the configured workflow.
The MISP integration for Security Operations provides a base system sighting search profile that enables you to configure automatic sighting searches. With this profile, you can access the related observable sighting information of an organization and also see the external sightings from other organizations.