---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Operations Integration - Sightings Search Flow

# Security Operations Integration - Sightings Search Flow {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Security Operations Integration - Sightings Search flow is a high-level flow independent of integrations. It uses the configured queries to search for a set of observables based on the configured
integrations which support the capability. Use it to fulfill an integration such as Splunk or Elasticsearch.

## Before you begin

Role required: sn_si.analyst

## About this task

If a security incident has an observable attached to it, this flow is triggered when you click on Run Sighting Search in the Actions on selected rows... drop-down menu in the
Security Incident Observables tab.  
Figure 1. Sightings Search

Activities specific to this flow are described here. For more information on other activities, see [Common Security Operations integration flows and orchestration activities](https://servicenow-prod.fluidtopics.net/VeHrUh9NzKmFfa~3wxWcqQ "Many of the flows associated with third-party integrations include the same activities. For example, activities for beginning and completing processing.").
* **[Sightings Search - Determine Observables activity](https://servicenow-prod.fluidtopics.net/obUbLm55KaN0IKNtgh4cMQ)**   
  The Sightings Search - Determine Observables workflow activity determines which observables to include in the workflow.
* **[Persistent Observable Sightings activity](https://servicenow-prod.fluidtopics.net/FTmaQ1QTkZetIFcTC6ngnQ)**   
  The Persistent Observable Sightings workflow activity retrieves observables from the third-party integration.
* **[Get Observable Sightings Queries activity](https://servicenow-prod.fluidtopics.net/cXprP16uLjwrBNZ8cNqa_Q)**   
  The Get Observable Sightings Queries workflow activity retrieves queries from the integration configuration.
* **[Security Operations - Arcsight Logger Sightings Search Flow](https://servicenow-prod.fluidtopics.net/FQJwjT30bP8xH1D85Mf~6w)**   
  Security Operations - ArcSight Logger Sightings Search flow is the implementation for the Splunk integration launched by the Security Operations Integration - Sightings Search Flow.
* **[Security Operations - Elasticsearch Sightings Search Flow](https://servicenow-prod.fluidtopics.net/WlNDPef9Jnx5HTnbYw5bwA)**   
  Security Operations - Elasticsearch Sightings Search flow is the Elasticsearch implementation launched by the Security Operations Integration - Sightings Search flow.
* **[Security Operations - McAfee ESM Sightings Search Flow](https://servicenow-prod.fluidtopics.net/cFh7ANGSNIAuviTOSJoFMQ)**   
  Security Operations - McAfee ESM Sightings Search flow is the implementation for the McAfee Sighting Search implementation launched by the Security Operations Integration - Sightings Search Flow.
* **[Security Operations - QRadar Sightings Search Flow](https://servicenow-prod.fluidtopics.net/diXpjF4lauyt6Jq4FPkJOw)**   
  Security Operations - QRadar Sightings Search flow is the implementation for the IBM QRadar integration launched by the Security Operations Integration - Sightings Search flow.
* **[Security Operations Integration - Splunk Sightings Search Flow](https://servicenow-prod.fluidtopics.net/X07OwZ_Zwy~i_9~Y9lYjww)**   
  Security Operations - Splunk Sightings Search flow is the implementation for the Splunk integration launched by the Security Operations Integration - Sightings Search flow.

