Run a Sightings Search
Determine the prevalence of a threat over time or test remediation or eradication efforts. You can select individual or multiple observables and the date range for your search from a security incident. Results are included in the Security Incident Observables related list.
Before you begin
Role required: sn_si.analyst
About this task
Note:
An active implementation must be configured. Sightings Search supports Elasticsearch, Splunk, McAfee ESM, HPE ArcSight Logger, and QRadar incident
enrichment. If no implementations are available, capability actions, such as Run Sightings Search, are not displayed in product menus.