---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# View information in a security incident

# View information in a security incident {#ariaid-title1}

* Release version: Australia
* 
* Updated August 11, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can perform several other actions on an existing security incident using the
related links.

## Before you begin

Role required: sn_si.basic

## Procedure

1. If it is not already open, open the security incident you want to update.
2. Within Related Links, you can perform the following tasks,

   | Option | Description |
   | [View Manual Runbook](https://servicenow-prod.fluidtopics.net/EjEx2i4_BJB~IAh6cy32sQ#create-runbook "A runbook is an association between a published knowledge article and a specific task. While you are performing the task, a knowledge article in the runbook automatically opens, providing information pertinent to the task.") | View a list of runbooks available for this security incident. |
   | Response Workflow | View any workflow associated with this incident. |
   | [Add Multiple Observables](https://servicenow-prod.fluidtopics.net/FSHOfAoQ1XfxZiv6I6YNtQ "To save time, you can add multiple security incident observables to the security incident observables list.") | Adds a list of observables in comma, new line, tab, or pipe delimited formats. |
   | [Add to Security Case](https://servicenow-prod.fluidtopics.net/Y2pnftV6QRdUlHoNUrOfNA "Security Case Management provides a means for security analysts who are engaged in threat hunting to gather information on suspicious activity in their environment. Case-related records, such as security incidents, observables, CIs, and affected users can be added to cases to accommodate broad and specific analysis.") | Adds the security incident to one or more security cases. You can also create a new security case and add this security incident to it. |
   | Get QRadar IP Summaries | If a QRadar integration is available, and contains valid CIs, source, and destination IP addresses, it triggers the QRadar workflows and displays the results in work notes. |
   | Run Orchestration | Choose and run a Security Operations workflow. |
   | [View SLA timeline](https://www.servicenow.com/docs/access?context=t_ViewSLATimeline&version=australia&pubname=australia-it-service-management&ft:locale=en-US) | You can view an SLA timeline from a Task SLA record or from an SLA definition. |
   | Show All Related Lists | Displays all standard related lists and any lists added manually. Note: Manually added items are available only in this view. |
   | [Show Affected Items](https://servicenow-prod.fluidtopics.net/v5P23O5qpqXvK~jeo5tUXw "You can view affected items, such as CIs, affected users, unmatched affected users, and affected services associated with a security incident.") | Displays the lists of CIs, users, and services directly affected by this incident |
   | [Show Related Items](https://servicenow-prod.fluidtopics.net/5dWDw6sQ~pOrALbzetUbNg "You can view related items, such as similar and child security incidents, related users, vulnerability groups, and vulnerable items associated with a security incident.") | Displays the lists of related incidents, CIs, users, and groups affected by this incident. |
   | [Show IoC](https://servicenow-prod.fluidtopics.net/QiPYhovl9Rh2EBQRXKLqlA "You can view IoC information, such as observables and sightings search results associated with a security incident.") | Displays the lists of observables, indicators, malware, modes and methods, and security scan requests associated with this incident. |
   | [Show Enrichment Data](https://servicenow-prod.fluidtopics.net/vfRbfkT4oIhy008Ej9qB8g "You can view enrichment data, such as running processes, running services, and network statistics associated with a security incident.") | Displays the lists of enrichment data, processes, services, statistics, lookups, firewall logs, and compromised user information associated with this incident. |
   | [Show Response Tasks](https://servicenow-prod.fluidtopics.net/w0eTEV1T~Ug1aQGp91dl0A "You can view response task information, such as task SLAs, risk score audits and outages associated with a security incident.") | Displays the lists of tasks, SLAs, risk score audits, outages, and Exchange searches associated with this incident. |
   | View Details in External System | If this security incident was generated from an external application, directly or by events, and a link to the originating data was provided, the View Details in External System action opens the URL. You can view and search through the logs that generated this incident. |
   | [Scan for Vulnerabilities](https://servicenow-prod.fluidtopics.net/ecz0w4HpimImD2MbQPy6~g "An IoC lookup automatically runs whenever observables are added to a security incident. Also, if your security incident has attachments, they can be easily found with the press of a button.") | If Vulnerability Response is activated, and you have selected at least one affected CI for the security incident, you can submit a scan request to determine what vulnerabilities exist on the CI. |
   |-|-|

   {#perform-addtl-tasks-on-si__choicetable_k4s_q45_c5}

