---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create an observable from a case

# Create an observable from a case {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

New observables can be created from cases in Security Case Management.

## Before you begin

Role required: sn_ti.case_user

## Procedure

1. Navigate to AllThreat IntelligenceCase ManagementAll Cases.  
   The Security Cases list opens.
2. Either open an existing case or click New to [create a new case](https://servicenow-prod.fluidtopics.net/F~AwqEo772k8dyZZlQaMnA "Cases are used to track information about a campaign or state actor threatening your organization. After a case is created, you can add artifacts that allow you to review and analyze all related information within a single case record.").
3. Click the Case Artifacts related link and click the Observables tab.
4. Click New and enter the requested information.  
   {#create-an-observable-from-a-case__table_t4d_4bd_5s__entry__2}

   | Field | Description |
   |-|-|
   | Value | \[Read only\] The case number. |
   | Observable type | Enter a descriptive name for the case. |
   | Observable type category | Select the type of case being investigated. |
   | Incident count | Select the importance of this case (from Critical to Low). |
   | Finding | \[Read only\] The date and time the case was last updated. |
   | Notes | A brief description of the case. |
   [ ]

   {#create-an-observable-from-a-case__table_t4d_4bd_5s}
5. Click the Additional Case Details tab.
6. Fill in the fields as appropriate.  
   {#create-an-observable-from-a-case__table_ecw_znv_xy__entry__2}

   | Field | Description |
   |-|-|
   | Created by | \[Read only\] The name of the user who created this case. |
   | State | The current state of the case. At case creation, the State defaults to Draft. |
   | Work notes list | Click the check box to display the work notes in the Additional Case Details section of the case record. |
   | Work Notes | If needed, type a work note for the case. If the Work notes list is selected, the work note appears in the Additional Case Details section of the case record. |
   [ ]

   {#create-an-observable-from-a-case__table_ecw_znv_xy}
7. Click Submit.  
   As needed, you can click the Case Artifacts tab and [add artifacts to the
   case](https://servicenow-prod.fluidtopics.net/pRIpTBzc8pYtBEji6ua~zg "After you have created a case, you can add artifacts, such as security incidents, CIs, and indicators of compromise, to the case. These artifacts act as clues in solving the case.").
{#create-an-observable-from-a-case__steps_g5g_wkr_dz}
**Related tasks**   

* [Create a case from IoCs or observables](https://servicenow-prod.fluidtopics.net/Wg2HQ5CJenZRoqL4hcuatQ "In Threat Intelligence, you can create a case from artifacts (IoCs or observables). After the IoCs or observables have been used to create a case, you can use Security Case Management to analyze the data.")
* [Add IoCs and observables to an existing case](https://servicenow-prod.fluidtopics.net/k7LgOZHvnOw7b_J1FA4pwg "You can add IoCs and observables to existing cases. After the security incidents have been added to cases, you can use Security Case Management to analyze the data.")
* [Run a sightings search on observables in a case](https://servicenow-prod.fluidtopics.net/XvGr49U2CMh76ejxomO4Mw "You can search for observables using the Sighting Search feature to determine how often they occur. Each occurrence is considered a sighting. You can limit the search to the number of sightings within a selected number of days or within a date range.")

*[\>]: and then


