---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Explore correlation insights

# Exploring correlation insights {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Exploring correlation insights

ServiceNow's Security Incident Response (SIR) application enables you to generate correlation insights to efficiently investigate and resolve security incidents.
These insights help avoid duplicate investigations by identifying related affected users, configuration items (CIs), and observables linked to a security incident.
This feature is available starting with version 3.0.0 of ServiceNow Otto for SIR and can be accessed through the Security Incident Response Workspace or the legacy UI (UI16).
Show full answer Show less  

## Key Features

* **Customizable Correlation Criteria:** Select specific CIs or affected users from related lists to base correlation insights on, allowing more precise and relevant investigation data.
* **Multi-Item Insight Generation:** Generate correlation insights simultaneously for multiple associated observables, CIs, and affected users.
* **Time Range for Lookup:** Correlation searches cover the last 30 days by default, with insights stored per observable until regenerated with a different time range.
* **Modeless Dialog Display:** Results are presented in a movable and resizable dialog within the workspace, facilitating easy review without obstructing workflow.
* **ServiceNow Otto Panel Integration:** Generate and view correlation insights directly from the Otto panel, available in both the Security Incident Response Workspace and UI16 once the relevant skill and panel are activated.
* **Access Control:** Insight results depend on your access to specific tables such as Configuration item, Incident, Change request, Problem, Vulnerable item, and Associate observable tables. Proper roles and applications (e.g., Vulnerability Response) are required to view certain data types.

## Practical Application

To use correlation insights effectively, ensure that the correlation insights generation skill and the ServiceNow Otto panel are activated. You can generate insights from incidents in any state and filter correlation criteria via the Details tab or related lists. The feature helps you quickly identify related incidents and affected entities, streamlining incident resolution.

You can reset the conversation in the Otto panel to clear your search criteria and results, enabling fresh investigations.  
Generate correlation insights to avoid duplicating your investigation into affected users, configuration items, and observables and resolve the security incident that you're working on quickly. You select the criteria from a
security incident that you want to base the correlation insights on.

## Generating correlation insights from the Security Incident Response Workspace {#generating-insights-for-now-assist-for-security__section_pkk_jpc_t2c}

Starting with v3.0.0 of ServiceNow Otto for Security Incident Response (SIR), generate and view correlation insights and view the results in the Security Incident Response Workspace.

* Previously, if you selected a configuration item (CI) or affected user to base your insights on, the lookup returned the primary affected user or primary CI associated with a security incident. Starting with v3.0.0 the agent asks you which CI or Affected user you would you like to correlate the security incident with from the related lists.
* You can generate correlation insights from the Investigation tab for a security incident in any state in the Security Incident Response Workspace.
* You can generate insights for multiple items simultaneously for Associated Observables, Configuration items, and Affected Users.
* Results are displayed in a modeless dialog that you can resize and move.
* Your time range for the lookup of correlation is 30 days.  
  Note:  
  After you generate an observable associated with a security incident, the insights are stored for that observable until you regenerate it with a different time range. Your insights for your new time range are displayed.

{#generating-insights-for-now-assist-for-security__ul_rkr_mrc_t2c}

The correlation insights generation skill must be activated before you can see the Generate correlation insights option in the Security Incident Response Workspace. For more information, see [Configure a skill for ServiceNow Otto for Security Incident Response (SIR)](https://servicenow-prod.fluidtopics.net/6T5hdprj0Jah0M913wCb8Q "Configure and review the details for a skill in the Guided Setup. You can edit and reactivate a skill from the Guided Setup.").

## Generating correlation insights from the ServiceNow Otto panel in the Security Incident Response Workspace and in UI (UI16) {#generating-insights-for-now-assist-for-security__section_bxv_sb5_ydc}

The correlation insights generation skill must be activated before you can see the Generate correlation insights option in the ServiceNow Otto panel.

If you don't see the panel, you must activate it. For more information, see [Activate the ServiceNow Otto panel standard chat](https://www.servicenow.com/docs/access?context=activate-now-assist-panel&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US).

* You can generate correlation insights from a security incident record in any state in the Security Incident Response Workspace or in the legacy UI (UI16).
* By default, correlation insights search for matching records from the last 30 days.
* You can locate and review values for the Configuration item, Affected user, and Observables for correlation insights filters on the Details tab in the Security Incident Response Workspace, or on the Configuration Items, Affected Users, and Observables related lists in the legacy UI (UI16).
* Your search criteria and results remain displayed in the panel until you reset the conversation. To reset your conversation, select the More options icon (![More options menu icon.]()) in the panel and select Reset Conversation.
* You must have access to the following tables to view these records in the generated correlation insights:
  * Configuration item \[cmdb_ci\] table.
  * Incident \[incident\] table.
  * Change request \[change_request\] table.
  * Problem \[problem\] table.
  * Vulnerable item \[sn_vul_vulnerable_item\] table.
  * Associate observable \[sn_ti_observable\] table.
  {#generating-insights-for-now-assist-for-security__ul_gcw_rbb_zdc}
* Your results for correlation insights are based on the tables that you have access to. For example, if you want to view vulnerable items (VIT)s in your correlation insights results, you must have the Vulnerability Response application installed and the read access role (sn_vul.read_all).

{#generating-insights-for-now-assist-for-security__ul_jfn_125_ydc}

For the steps to generate correlation insights, see [Generate correlation insights](https://servicenow-prod.fluidtopics.net/lAJ218TTP52qfVkBWeV1yg "Generate and view correlation insights in the Security Incident Response Workspace to help you connect past events to the security incident you're working on.") and [Generate correlation insights in the ServiceNow Otto panel](https://servicenow-prod.fluidtopics.net/nd7OD2F4ij~YsTFxxZT2QA "Generate correlation insights from the ServiceNow Otto panel to help you connect past events to the security incident that you're working on.").

