---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Add observables to TISC Case

# Add observables to TISC Case {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Add observables to TISC case records.

## Before you begin

Role required: sn_si.analyst, sn_sec_tisc.case_write

## Procedure

1. Navigate to WorkspacesSecurity Incident Response WorkspaceSecurity IncidentsAll.
2. Locate and open any specific security incident that you are investigating.  
   This can also be done by searching for the incident ID or browsing from Quick Filters section or filtering through incident state.
3. Click on the Related Records tab on the workspace.  
   You can perform the action of adding observables to TISC case(s) using various tabs from the Security Incident Response Workspace.  
   Note:  
   You can navigate to the
   * Observables details page from the Related Records tab.
   * Investigation tab, and navigate to the Entry Points Lists section displayed on the left side of the page and select Associated Observables to add observables to TISC case.
   {#observables-to-case__ul_g25_xlb_h1c}
4. For example, select Threat IntelAssociated Observables.
5. Select one or multiple observable(s) to add the selected observables to case records.  
   Note:  
   You can also click on any of the Observable record and it opens Observables details page in a different tab and you can add case records from here by clicking on Add to TISC Case.
6. Click the Capability actions split button.
7. Select Add to TISC Case.
8. Select the case(s) from the Add to Case dialog box.  
   Note:  
   Create a new TISC case if there no case records. For more information on how to create case(s), see [Creating cases using Threat Analyst Workbench](https://servicenow-prod.fluidtopics.net/Xb8x3ylFD6FijaDvKqX3WA "Cases are used to track information about a campaign or threat actor threatening your organization. After a case is created, you can add artifacts that allow you to review and analyze all related information from a single case or case task.").
9. Click Add.
10. Click the Case record to view the case in TISC from the information message displayed or from the Activity stream.  
    Note:  
    If the observable does not have a corresponding TISC Observable, then the selected observable in SIR workspace will be sent to TISC automatically and will subsequently gets added to the selected TISC case record(s). To view the linked observables, click on the particular case record from the Activity stream. By clicking on this will take you to the case record in TISC workspace and the observables will get added under Artifacts tab of the Case Management module.

## Result

You have successfully send the observables data to Threat Intelligence Security Center case management.
**Related tasks**   

* [Add security incident to TISC case](https://servicenow-prod.fluidtopics.net/oRyoXHXc6vM0yC1H_dAqDQ "Add security incidents to TISC case records.")
* [Send Observables to TISC](https://servicenow-prod.fluidtopics.net/VJNWnxlhS9MGhvva17pqgw "Using this feature the security analyst can push the observables data from SIR to TISC. Using the TISC Context, you can check if the observables are present in TISC, if not security analyst can push the data whenever required.")
* [Send Threat Lookup to TISC](https://servicenow-prod.fluidtopics.net/QQdzzepm419PH_VxjzMw9w "Using this feature the security analyst can push the threat lookup data from SIR to TISC. Using the TISC Context, you can check if the threat lookup results are present in TISC, if not security analyst can push the data whenever required.")
* [Send Sighting Search to TISC](https://servicenow-prod.fluidtopics.net/lrH4qlEmdq1zowWEOb~Cbw "Using this feature the security analyst can push the sighting search data from SIR to TISC. Using the TISC Context, the analyst can check if the sighting search data is present in TISC, if not the security analyst can push the data whenever required.")
* [Send Observable Enrichment to TISC](https://servicenow-prod.fluidtopics.net/d_zRa7QF_uxPqTH8ByInUg "Using this feature the security analyst can push the sighting search data from SIR to TISC. Using the TISC Context, the analyst can check if the sighting search data is present in TISC, if not the security analyst can push the data whenever required.")  
**Related reference**   

* [System properties to send data](https://servicenow-prod.fluidtopics.net/xQZzhDOp9JP7rBFciK40Ow "Review the system properties for TISC integrations to combine with SIRW. You can configure these properties to control how both applications manages the integrations.")

*[\>]: and then


