---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Edit a security incident observable list

# Edit a security incident observable list {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can edit which observables in the list associated with a security incident to
display.

## Before you begin

Role required: sn_si.basic

## Procedure

1. Navigate to Security Incident.
2. Choose an incident.
3. Select the Security Incident Observables related list tab.
4. Select Edit.
5. Add or remove observables from the list.  
   Create a filter for long lists.
6. Select Save.  
   Note:  
   When you add an observable to the security incident, the system checks for any other configuration items or users associated with it. The Related Configuration Items and Related Users related list tabs are updated accordingly. Also, if the Threat Intelligence plugin is activated, and you have at least one [Security Incident Response integrations](https://servicenow-prod.fluidtopics.net/RhaRoT0Fn_2fkoMqo0mGDA "Security Incident Response (SIR) integrates with third-party security tools to create security incidents.") integration implementation activated, the [Security Operations Integration - Threat Lookup capability](https://servicenow-prod.fluidtopics.net/aKsui0~8zhutMOFnbigrAA "The Threat Lookups capability performs threat intelligence lookups to determine whether one or more observables are associated with known security threats.") executes one or more workflows, and threat security lookups are performed on the observables you added. The results appear in the Threat Lookup Results tab.
**Related tasks**   

* [Add multiple security incident observables](https://servicenow-prod.fluidtopics.net/FSHOfAoQ1XfxZiv6I6YNtQ "To save time, you can add multiple security incident observables to the security incident observables list.")
* [Create a security incident observable](https://servicenow-prod.fluidtopics.net/fPLnzEL94u1VuhKG8xqEtQ "You can create and view an observable within a security incident and take appropriate action. Having observables available in the security incident is scalable and reduces response time.")

