Invoke the sightings search from a SIR security incident by following the below
procedure.
Before you begin
Role required: ServiceNow AI Platform administrator (sn_si.admin)
Procedure
-
Navigate to the Security Incidents.
-
Open any existing SIR or create a new SIR.
-
Click Show IoC in Related Links.
-
Click related lists.
-
Add any existing observables or create new observable.
-
Select the observables and from Actions on selected rows, click .
-
Ignore the inputs in the next dialog box that asks for time data.
There are default values populated. However, the search is performed real time
and the time values are ignored for this integration.
-
Check the worknotes for status.
-
On completion of the search, check the results and details in the related
lists.
-
Click on tab for details and tab for search results.