---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Define queries for Sighting Search

# Define queries for Sighting Search {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 min. de leitura

You can use sighting search configurations for defining the queries used to find the prevalence of observables in your environment as part of observable investigation.

## View queries for Sighting Search {#manage-sighting-search-configurations__section_gcx_mg3_pzb}

Role required: sn_sec_tisc.admin  
To view the sighting search configurations, perform the following steps:

1. Navigate to WorkspacesThreat Intelligence Security CenterIntegrations.
2. From the Integrations page, navigate to Enrichment IntegrationsSighting Search.
3. Look for the integration for which you want to view the Sighting Search Configuration, and click Edit.
4. Select the Sighting Search Configurations tab.

   You can view the list of sighting search configurations.

5. Click on the required Sighting Search Configuration to view the details of the configuration.
6. To generate a test sighting search query, click the Generate Test Sighting Search Query action.  
   Nota:  
   The Generate Test Sighting Search Query action would only work if you had configured sighting search query parameters. For more information, see [Using Sighting Search Parameters](https://servicenow-prod.fluidtopics.net/o~WwK8Ti5MpikwGyfwgubg "You can use sighting search parameters that define more complex queries, which include logic and other operators supported by the specified log store.").
7. In the Generate Test Sighting Search Query pop-up, enter or paste multiple observables using comma, new line, tab, or pipe separators to generate a test query.
8. Click Generate to generate the test sighting search query.
9. You can also perform the following actions on the Sighting Search Configurations tab:
   1. To refresh the list of sighting search configurations, click the ![Refresh option]() icon.
   2. To perform a list action on the sighting search configurations, click the ![List actions]() icon.  
      You can perform the following two list actions:
      * Edit columns: You can use this action to add or remove existing columns and modify the order according to your requirements.
      * Reset widths: You can use this action to reset the widths of the columns.
      {#manage-sighting-search-configurations__ul_xmg_1dw_4zb}
   3. To filter sighting search configurations based on conditions, click the ![Filter panel]() icon.

      The value 1 indicates that one condition is used for the filtering.
   {#manage-sighting-search-configurations__ol_urc_n33_pzb}
{#manage-sighting-search-configurations__ol_wb3_bh3_pzb}

## Create Sighing Search Configurations {#manage-sighting-search-configurations__section_fmg_4g3_pzb}

Role required: sn_sec_tisc.admin  

    Maximum observables per search = "maximum number of observables that can be substituted in a single search query"

    Search = "Search query that should be executed in sighting search source. 
    Search query can contain substitution variables that would be substituted with observables of specific type as configured in sighting search parameters when sighting search query is formed"

To create a sighting search configuration, perform the following steps:

1. Navigate to WorkspacesThreat Intelligence Security CenterIntegrations.
2. From the Integrations page, navigate to Enrichment IntegrationsSighting Search.
3. Look for the integration for which you want to view the Sighting Search Configuration, and click Edit.
4. Select the Sighting Search Configurations tab.

   You can view the list of sighting search configurations.
5. To create a sighting search configuration, click New.

6. On the form, fill the fields.{#manage-sighting-search-configurations__table_zw2_g53_pzb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name for the sighting search configuration. |
   | Observable type | Defines the type of observable category. |
   | Sightings search source | Defines the source configured for the integration. |
   | Maximum observables per search | The number of observables before the search query is split into multiple queries. Set this value to <kbd class="ph userinput">500</kbd> for this integration. |
   | Search | Add a native search string to form a query. For example, <kbd class="ph userinput">${observable}</kbd>. |
   | Is saved search | Runs a saved search, that is, the Name field should match the name of the saved search. |
   | Active | Query runs only if it active option is selected. |
   [Tabela 1. Create a sighting search configuration]

   {#manage-sighting-search-configurations__table_zw2_g53_pzb}
7. Click Save.
{#manage-sighting-search-configurations__ol_ivt_tt3_pzb}

