---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure MISP sighting searches

# Configure MISP sighting searches {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Configure the ServiceNow AI Platform to do sighting searches for observables in the
MISP instance. With this information, you can determine how often threats
occur.

## Before you begin

* [Review the MISP user role and permissions](https://servicenow-prod.fluidtopics.net/2KlTp_H05hz5YKtE5U7caw "Review the user roles that are required in the MISP integration for Security Operations integration.") that are required for using the MISP bi-directional features.
* Role required: sn_si.admin, sn_ti.admin
{#configure-sightings-search__ul_z5v_bts_mqb}

## About this task

The [Security Operations Integration - Sightings Search workflow](https://servicenow-prod.fluidtopics.net/h_dAICTJQ0lbJ~eF~zxSLA "Security Operations Integration - Sightings Search flow is a high-level flow independent of integrations. It uses the configured queries to search for a set of observables based on the configured integrations which support the capability. Use it to fulfill an integration such as Splunk or Elasticsearch.")
executes the sighting searches. This workflow accepts a list of observables, finds
any implementing capabilities, creates the queries that are based on the sighting
search configurations, and executes the searches that are based on the configured
workflow.

The MISP integration for Security Operations provides a base system sighting search profile
that enables you to configure automatic sighting searches. With this profile, you
can access the related observable sighting information of an organization and also
see the external sightings from other organizations.

## Procedure

1. Navigate to AllMISP IntegrationSighting Search Configuration.
2. Click New.
3. On the form, fill in the fields.  
   {#configure-sightings-search__table_qbq_rzf_lqb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name for the capability profile. |
   | Is saved search | Search configuration that is saved when you select this option. The saved search configuration queries are example queries. You can substitute them with the parameters for your environment and create additional saved search configurations as required. |
   | Sightings search source | Source for the sightings search. Select the MISP log store as the source. |
   | Active | Option that enables the saved search configuration. Only active search configurations can perform a sightings search. |
   | Observable type | Observable type such as the IP address, hash value, URL, and domain name. |
   | Maximum observable per search | Maximum number of observables that you can view from a search query. |
   | Search | Default search string that is ` $(observable)`. However, you define your own search query by specifying the MISP log store supported parameters. |
   [Table 1. Sightings Search Configuration form]

   {#configure-sightings-search__table_qbq_rzf_lqb}
4. Click Submit.

## Result

You created a MISP sightings search configuration profile.
**Related concepts**   

* [MISP event data](https://servicenow-prod.fluidtopics.net/vO7Gn3bAzNeDSfQ6VkL_ag "You can review the MISP event data so that you can see detailed information about the MISP events.")
* [Troubleshooting MISP integration](https://servicenow-prod.fluidtopics.net/W5V1EqvFYQGGq7dNvNSUNw "This section covers important troubleshooting tips that can help you resolve common issues you can encounter when setting up or running MISP integration.")  
**Related tasks**   

* [Install and configure the MISP integration for Security Operations](https://servicenow-prod.fluidtopics.net/zOAgaNpmJ0mhPEIijntI9A "Install and configure the MISP integration for Security Operations from the ServiceNow Store on your ServiceNow AI Platform instance so that you can start investigating security incidents using the MISP data.")
* [Review the MISP integration settings](https://servicenow-prod.fluidtopics.net/QxVygHLr4q6T8yd6jye~0w "Review the MISP integration for Security Operations settings and modify the default system properties to suit your environment.")
* [Configure how an automatic event is created](https://servicenow-prod.fluidtopics.net/MEkw3eZtEjMG30VJSZAlNg#configure-automatic-event-creation-profile "Configure the ServiceNow AI Platform to automatically create events in MISP.")  
**Related reference**   

* [Getting started with MISP integration for Security Operations](https://servicenow-prod.fluidtopics.net/EFFaGnNJvZjqxuXFXJT3Og "Review the following information before you set up your MISP integration for Security Operations.")
* [Associated MISP events](https://servicenow-prod.fluidtopics.net/cUrghVC4~oQonIE2_u3kpQ "You can use the associated MISP events list view to view the events that have been created manually or automatically in the context of a security incident.")
* [MISP user information](https://servicenow-prod.fluidtopics.net/sMMXkR0Wmfb~llmc4~6S7w "You can use the MISP user information page to view all the associated users for the ServiceNow AI Platform MISP integration for Security Operations.")
* [Domain separation and MISP](https://servicenow-prod.fluidtopics.net/Cs4ZJeHmQkXB9cNNcFHTgw "Domain separation is supported in MISP. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.")

*[\>]: and then


