---
sourceDocument: Zurich Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/security-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Get started with Sighting Search Configurations

# Get started with Sighting Search Configurations {#ariaid-title1}

Release version: Zurich  
Updated April 27, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read  
Sighting Search Configurations define how threat intelligence data is searched and matched against your environment. Configure these settings to customize threat detection and improve security monitoring accuracy.

The Elasticsearch and Splunk Sighting Search integrations enrich observables with sighting information from your log data. Elasticsearch searches logs to add relevant sightings directly to observables, while Splunk searches, monitors, and analyzes machine-generated data across Security Operations. Download the Splunk Sighting Search integration from the ServiceNow Store.
* **[Configure and enable Elasticsearch integration](https://www.servicenow.com/docs/RxxlyaJkWYNmr~Mka0BrGg)**   
  Elasticsearch is a distributed, RESTful search and analytics engine that easily integrates with Security Operations.
* **[Configure and enable Splunk integration](https://www.servicenow.com/docs/lohovDCw9iLaMuE1cxKlZA)**   
  Configure the Splunk Enrichment integration to automatically search your logs and add relevant sighting information to threat intelligence data.
* **[Configure CrowdStrike NextGen SIEM sighting search](https://www.servicenow.com/docs/NCQaZvFzTPYbXTqKhXtK5Q)**   
  Configure the CrowdStrike NextGen SIEM integration with your Falcon API credentials so that analysts can search CrowdStrike log data for activity that matches an observable.

