---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Add multiple security incident observables

# Add multiple security
incident observables {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

To save time, you can add multiple security incident observables to the security
incident observables list.

## Before you begin

Role required: sn_ti_write  
Note:  
When adding multiple security incident observables, duplicates are ignored during processing.

## Procedure

1. Navigate to Security Incident.
2. Choose an incident.
3. Select the Investigation tab.
4. Select Associated Observables.
5. Select Multiple New from the more options.
6. Enter or paste multiple observables.  
   Entries can be of any Observable Type. Accepted formats are: comma, new line, tab, or pipe separators.  
   Note:  
   When you add an observable to the security incident, the system checks for any other configuration items or users associated with it. The Related Configuration Items and Related Users related list tabs are updated accordingly. Note: Observable values not auto-detected are assigned to type Unknown.
7. Select Submit.
{#add-multiple-si-observables__steps_j3s_qvn_zx}

