---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Operations Integration - Sightings Search Flow

# Security Operations Integration - Sightings Search Flow {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

Security Operations Integration - Sightings Search flow is a high-level flow independent of integrations. It uses the configured queries to search for a set of observables based on the configured
integrations which support the capability. Use it to fulfill an integration such as Splunk or Elasticsearch.

## Antes de Iniciar

Role required: sn_si.analyst

## Por Que e Quando Desempenhar Esta Tarefa

If a security incident has an observable attached to it, this flow is triggered when you click on Run Sighting Search in the Actions on selected rows... drop-down menu in the
Security Incident Observables tab.  
Figura 1. Sightings Search

Activities specific to this flow are described here. For more information on other activities, see [Common Security Operations integration flows and orchestration activities](https://servicenow-prod.fluidtopics.net/KMDauzEgIIpChAc9WGx3Sg "Many of the flows associated with third-party integrations include the same activities. For example, activities for beginning and completing processing.").
* **[Sightings Search - Determine Observables activity](https://servicenow-prod.fluidtopics.net/uM1s_jjkuJ3zBK3FQpoFoQ)**   
  The Sightings Search - Determine Observables workflow activity determines which observables to include in the workflow.
* **[Persistent Observable Sightings activity](https://servicenow-prod.fluidtopics.net/otagDdrcwv1hUMqOI_r~tQ)**   
  The Persistent Observable Sightings workflow activity retrieves observables from the third-party integration.
* **[Get Observable Sightings Queries activity](https://servicenow-prod.fluidtopics.net/WjyOmf_7F9ak6qcDPcX3Ow)**   
  The Get Observable Sightings Queries workflow activity retrieves queries from the integration configuration.
* **[Security Operations - Arcsight Logger Sightings Search Flow](https://servicenow-prod.fluidtopics.net/CDUT~gzSQRoPJOXb6Ir7FA)**   
  Security Operations - ArcSight Logger Sightings Search flow is the implementation for the Splunk integration launched by the Security Operations Integration - Sightings Search Flow.
* **[Security Operations - Elasticsearch Sightings Search Flow](https://servicenow-prod.fluidtopics.net/dqB5h~~O46KvvufWVRvUog)**   
  Security Operations - Elasticsearch Sightings Search flow is the Elasticsearch implementation launched by the Security Operations Integration - Sightings Search flow.
* **[Security Operations - McAfee ESM Sightings Search Flow](https://servicenow-prod.fluidtopics.net/E2o1ihq3sE~P1UTVJnzdGQ)**   
  Security Operations - McAfee ESM Sightings Search flow is the implementation for the McAfee Sighting Search implementation launched by the Security Operations Integration - Sightings Search Flow.
* **[Security Operations - QRadar Sightings Search Flow](https://servicenow-prod.fluidtopics.net/W2bSA49rYLObEj_iutARgQ)**   
  Security Operations - QRadar Sightings Search flow is the implementation for the IBM QRadar integration launched by the Security Operations Integration - Sightings Search flow.
* **[Security Operations Integration - Splunk Sightings Search Flow](https://servicenow-prod.fluidtopics.net/GuGAkjx1WdVwQgiWG7oKhw)**   
  Security Operations - Splunk Sightings Search flow is the implementation for the Splunk integration launched by the Security Operations Integration - Sightings Search flow.

