---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Edit a security incident observable list

# Edit a security incident observable list {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

You can edit which observables in the list associated with a security incident to
display.

## Antes de Iniciar

Role required: sn_si.basic

## Procedimento

1. Navigate to Security Incident.
2. Choose an incident.
3. Click Security Incident Observables related list tab.
4. Click Edit.
5. Add or remove observables from the list.  
   Create a filter for long lists.
6. Click Save.  
   Nota:  
   When you add an observable to the security incident, the system checks for any other configuration items or users associated with it. The Related Configuration Items and Related Users related list tabs are updated accordingly. Also, if the Threat Intelligence plugin is activated, and you have at least one[Security Incident Response integrations](https://servicenow-prod.fluidtopics.net/b2m6WQaD2ZcSsSdkfuWO7A "All the Security Operations core applications and non-core third-party integrations are available from the ServiceNow Store. This section provides instructions for activating the integrations and configuring both ServiceNow and third-party integrations. Also included are some basic guidelines for developing your own integrations, as well as details on specific integrations included in the base system.") integration implementation activated, the [Security Operations Integration - Threat Lookup capability](https://servicenow-prod.fluidtopics.net/EHxtdpa8nkoaWGwAhQ_32Q "The Threat Lookups capability performs threat intelligence lookups to determine whether one or more observables are associated with known security threats.") executes one or more workflows, and threat security lookups are performed on the observables you added. The results appear in the Threat Lookup Results tab.
**Tarefas relacionadas**   

* [Add multiple security incident observables](https://servicenow-prod.fluidtopics.net/PsRT1xch94ub~Vb33FkJEA "To save time, you can add multiple security incident observables to the security incident observables list.")
* [Create a security incident observable](https://servicenow-prod.fluidtopics.net/UdratR6pzu5ns3YdKs96WQ "You can create and view an observable within a security incident and take appropriate action. Having observables available in the security incident is scalable and reduces response time.")

