---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Add observables to TISC Case

# Add observables to TISC Case {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

Use this section to add security incidents or observables to a TISC case.

## Antes de Iniciar

Role required: sn_si.analyst

## Procedimento

1. Navigate to WorkspacesSecurity Incident Response WorkspaceSecurity IncidentsAll.
2. Locate and open any specific security incident that you are investigating.  
   This can also be done by searching for the incident ID or filtering using Quick Filters section or browsing through an incident state.
3. Select TISC Context tab.
4. Click Add to TISC Case button.  
   Add to TISC Case dialog box displays and this only shows the TISC cases where the record is not already associated.
5. Select the observables.
6. Select case(s) and click Add to add the cases to the observables and associate them to the security incident.  
   Nota:  
   You can also create a new case by clicking on Create new TISC Case, in case if you don't have any existing cases.
   The following confirmation messages are displayed:
   * The following observables are added as artifacts successfully.
   * The following observables are sent to TISC and will be subsequently be added to the selected TISC case(s) records.

   {#tisc-si-case__ul_mck_czt_bcc}  
   Nota:  
   The processing and association of the observables activities are posted in the activity stream as and when the association is completed.
7. View the associated case records by logging into Threat Intelligence Security Center Workspace for further steps.  
   For more information see, [TISC integration with SIR Workspace](https://servicenow-prod.fluidtopics.net/LntevdViJHag33wa~xJjGQ "TISC integration with SIR automatically attaches the context on the observables within the security Incident workspace for the Security analysts. Any new observables from SIR can be sent to TISC for further analysis by CTI team using the UI actions provides on the screens.").  
   Nota:  
   From the Security Incident Response workspace, you can also associate observables to case records from the Investigation and Related Records tabs.  
   Nota:  
   To associate observables from Investigation, follow the below procedure and to associate from Related Records explained here [Add observables to TISC Case](https://servicenow-prod.fluidtopics.net/vwzMQFV4F46bQ~3L_c85gw "Add observables to TISC case records.").You can also navigate to the Investigation tab, and navigate to the Entry Points Lists section displayed on the left side of the page and select Associated Observables to add observables to TISC case.

