---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Export intelligence data

# Export intelligence data {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

Use the export feature to manually export the intelligence data in various formats.

## Antes de Iniciar

Role required: sn_sec_tisc.analyst

## Por Que e Quando Desempenhar Esta Tarefa

Currently, the export functionality is limited to observables, indicators, and case management. The following procedure describes how you can export the observables data, and follow the same procedure to export the indicators
data.

## Procedimento

1. Navigate to WorkspacesThreat Intelligence Security CenterThreat Intel LibraryObservablesAll Observables.
2. Select any observable record.
3. Select Export.  
   Nota:  
   The Export button is enabled only when observables are selected for export. If no observables are selected, the button remains disabled.
4. Select the desired file type for export.  
   * Currently, the supported export formats are Excel, CSV, and STIX 2.1 JSON. Suppose, if your export type is Excel then the number of records that can be exported at a time is limited to 10,000, regardless of the selected format type.
   * If the selection exceeds 10,000 records, then an error message displays indicating that the maximum limit for the selected format type has been surpassed, and only the first 10,000 records will be exported.
   * If the export format is CSV and the record limit is exceeded, an alert message is displayed indicating that the export is in progress state, along with a link to view the export status. You can click the link to view the status, and refresh the record. Once it moves to processed state you can download the attachment.  
     Nota:  
     When you export records in STIX 2.1 format Traffic Light Protocol (TLP) definitions applied to the intelligence object are included in the export as TLP 2.0 marking definition objects. For more information, see [Define Marking Definition](https://servicenow-prod.fluidtopics.net/1OeQTfE4KEXSx~NH_OvuJw "Define marking definitions to handle and share the requirements for the data.").
   {#tisc-export-observables__ul_lrl_3tc_m3c}
5. Select Export.  
   Nota:  
   You can also view export data from the Imports/Exports module.  
   A confirmation message indicating that the export is successful and your download is complete displays.
**Conceitos relacionados**   

* [Understanding the Data Model](https://servicenow-prod.fluidtopics.net/EAFuW0_jHs7lNBPJfuA55Q "The data model and architecture of threat intelligence security center module is designed to support threat intelligence platform capabilities and different security views that provides detailed data for threat analysts.")
* [TISC Library Objects form view](https://servicenow-prod.fluidtopics.net/VKKNaK4Klsqz1vLQeg0e8w "The Threat Intelligence Security Center objects home page consists of the following features.")
* [TISC Library Repository](https://servicenow-prod.fluidtopics.net/TTt_Z0iYwX114FnauQWWGg "IoC repository contains STIX objects, each of these objects contain a specific piece of information.")
* [Automated Correlation](https://servicenow-prod.fluidtopics.net/zHYvr19zY2GzXh2fHu4RiQ "Automated correlation helps you to identify the relationships between observables, indicators, and objects.")  
**Tarefas relacionadas**   

* [Deleting threat intelligence library records](https://servicenow-prod.fluidtopics.net/edlJJ645J32oFtDFR0vzhQ "Delete threat intelligence library records such as observables, indicators, and objects.")
* [Confirm Potential Relationships from Related Records](https://servicenow-prod.fluidtopics.net/pwxiJ1vW8YcP186IvdmA4A "Confirm the relationships between the two SDOs.")

