Security Operations Integration - Enrich Observable flow

  • Versão de lançamento: Australia
  • Atualizado 12 de mar. de 2026
  • 1 min. de leitura
  • The Security Operations Integration - Enrich Observable sub flow allows you to enrich observables with additional information from a variety of sources using implementation flow designer.

    Antes de Iniciar

    Role required: sn_si.analyst

    Por Que e Quando Desempenhar Esta Tarefa

    This flow can be triggered from either Security Incident Response or Threat Intelligence in two ways.
    • by selecting one or more observables from the Observables list and selecting Run observable enrichment from the Actions on selected rows choice list.
    • by opening an observable record and clicking the Run observable enrichment related link.

    Either method then allows you to specify which implementations to be used to enrich the selected observables. The associated implementation flows are executed to perform the enrichment.

    Figura 1. Enrich Observable
    Security Operations Integration - Enrich Observable

    Actions specific to this flow are described here. For more information on other actions, see Common Security Operations integration flows and orchestration activities.