---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Publish observables to a third-party watchlist

# Publish observables to a third-party watchlist {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

You can publish one or more observables or associated indicators to a third-party
watchlist. Currently, the only implementation that supports this functionality is
CrowdStrike Falcon Host.

## Antes de Iniciar

Role required: sn_si.analyst

## Por Que e Quando Desempenhar Esta Tarefa

Nota:  
If no implementations are available, capability actions are not displayed in product menus.

## Procedimento

1. Navigate to a security incident.
2. Select Observables from the Related List tab.
3. Click Publish to Watchlist in the Actions on selected rows... drop-down menu.  
   The dialog box appears.
4. Enter or choose the implementation.  
   Nota:  
   A workflow is triggered by the [Security Operations Integration- Publish to Watchlist capability](https://servicenow-prod.fluidtopics.net/ERD57V5Zqz1cK3KdD5i~tQ "The Publish to Watchlist capability adds observables and indicators associated with a security incident to a third-party watchlist that monitors for security events and generates alerts. This capability is used as part of incident response during investigations.") when you select the CrowdStrike Falcon Host implementation.
5. Click Submit.
{#run-publish-watchlist__steps_wnh_jg1_xy}

