---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Publish observables to a third-party watchlist

# Publish observables to a third-party watchlist {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can publish one or more observables or associated indicators to a third-party
watchlist. Currently, the only implementation that supports this functionality is
CrowdStrike Falcon Host.

## Before you begin

Role required: sn_si.analyst

## About this task

Note:  
If no implementations are available, capability actions are not displayed in product menus.

## Procedure

1. Navigate to a security incident.
2. Select Observables from the Related List tab.
3. Select Publish to Watchlist in the Actions on selected rows... drop-down menu.  
   The Publish to Watchlist dialog box appears.
4. Enter or choose the implementation.  
   Note:  
   A workflow is triggered by the [Security Operations Integration- Publish to Watchlist capability](https://servicenow-prod.fluidtopics.net/sqRJetgV_urJTWNWGVogFA "The Publish to Watchlist capability adds observables and indicators associated with a security incident to a third-party watchlist that monitors for security events and generates alerts. This capability is used as part of incident response during investigations.") when you select the CrowdStrike Falcon Host implementation.
5. Select Submit.
{#run-publish-watchlist__steps_wnh_jg1_xy}

