Using Sighting Search Parameters

  • Release version: Xanadu
  • Updated August 1, 2024
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Using Sighting Search Parameters

    ServiceNow's Threat Intelligence Security Center enables you to define complex sighting search parameters to create advanced queries for threat investigations. These parameters allow the use of logic and operators supported by your specified log store, improving the precision and flexibility of your threat sightings searches.

    Show full answer Show less

    Accessing and Managing Sighting Search Parameters

    • Role Required: snsectisc.admin
    • Navigate to Workspaces > Threat Intelligence Security Center > Integrations, then to Enrichment Integrations > Sighting Search.
    • Select the integration and edit its Sighting Search Configurations to view or manage parameters.
    • Within the Sighting Search Parameters tab, you can view, refresh, filter, and customize the list of parameters.
    • List actions let you edit which columns display and apply filters to focus on specific parameters.

    Creating and Configuring Sighting Search Parameters

    To create a new sighting search parameter:

    1. Navigate to the relevant integration as above.
    2. Open the Sighting Search Parameters tab and click New.
    3. Complete the form fields, which include:
    Field Description
    After each value Text appended after each observable during query generation.
    Between each value Text placed between observables (e.g., "OR") to form logical connections.
    Before each value Text prepended before each observable in the query.
    Configuration Details of the search parameter’s configuration.
    Observable type Defines the category/type of observable (e.g., IP address).
    Substitution variable Name of the variable replaced by observable values in the query.

    After filling the form, click Save to create the parameter.

    Practical Example

    Given observables like IP addresses (e.g., 172.32.31.41 and 192.168.10.12) and a configuration that applies "ipaddress = " before each observable and "OR" between values, the generated query would be:

    ipaddress = 172.32.31.41 OR ipaddress = 192.168.10.12

    This demonstrates how the parameters allow dynamic and precise query construction based on multiple observables.

    Benefits for ServiceNow Customers

    • Enables creation of tailored, complex queries for threat sightings across integrated log stores.
    • Improves threat detection accuracy by leveraging logical operators and observable substitution.
    • Offers flexible management and customization of sighting search parameters through an intuitive UI.

    You can use sighting search parameters that define more complex queries, which include logic and other operators supported by the specified log store.

    View Sighting Search Parameters

    Role required: sn_sec_tisc.admin

    To view the sighting search parameters, perform the following steps:
    1. Navigate to Workspaces > Threat Intelligence Security Center > Integrations.
    2. From the Integrations page, navigate to Enrichment Integrations > Sighting Search.
    3. Look for the integration for which you want to view the Sighting Search Configuration, and click Edit.
    4. Select the Sighting Search Configurations tab.

      You can view the list of sighting search configurations.

    5. Click on the required Sighting Search Configuration to view the details of the configuration.

      Sighting Search Parameters tab

    6. Select the Sighting Search Parameters tab.

      You can view the list of sighting search parameters.

    7. Click on the required Sighting Search Parameter to view the details of the parameter.
    8. You can also perform the following actions on the Sighting Search Parameters tab:
      1. To refresh the list of sighting search parameters, click Refresh option icon.
      2. To perform a list action on the sighting search parameters, click the List actions icon.

        Edit columns: You can use this action to add or remove existing columns and modify the order according to your requirements.

      3. To filter sighting search parameters based on conditions, click the Filter panel icon.

        The value 1 indicates that one condition is used for the filtering.

    Create Sighting Search Parameter

    Example for query generation
    Configured Query: ${Observable}​
    
    Observables Substitutes for Sightings search: Obs1 , Obs2​
    
    Query: {Before each Value}Obs1{After each Value}{Between each value}{Before each Value}Obs2{After each Value}​
    
    ​
    
    Let observables are: 172.32.31.41 & 192.168.10.12​
    
    Query Formed with below configuration will be: “ip_address = 172.32.31.41 OR ip_address = 192.168.10.12”
    To create a sighting search parameter, perform the following steps:
    1. Navigate to Workspaces > Threat Intelligence Security Center > Integrations.
    2. From the Integrations page, navigate to Enrichment Integrations > Sighting Search.
    3. Look for the integration for which you want to view the Sighting Search Configuration, and click Edit.
    4. Select the Sighting Search Configurations tab.

      You can view the list of sighting search configurations.

    5. Click on the required Sighting Search Configuration to view the details of the configuration.
    6. Select the Sighting Search Parameters tab.

      You can view the list of sighting search parameters.

    7. To create a sighting search parameter, click New.

      Create a Sighting Search Parameter

    8. On the form, fill the fields.
      Table 1. Create a sighting search parameter
      Field Description
      After each value The sighting search parameter after each observable when the search query is generated.
      Between each value The sighting search parameter between each observable when the search query is generated. For example, OR.
      Before each value The sighting search parameter before each observable when the search query is generated.
      Configuration The configuration details of the search parameter.
      Observable type Defines the type of observable category.
      Substitution variable Specifies the name of the variable that is replaced by an observable value.
    9. Click Save.