---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Manage observables

# Manage observables {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Observables are artifacts found on a network or operating system that are likely to
indicate an intrusion. Typical observables are IP addresses, MD5 hashes of malware files or URLs,
or domain names. Threat Intelligence
observable table data is available from within a security incident.

Observables information includes value, type, context, and timestamp.

You can create or delete observables manually or automatically through lookup requests.

A new Finding column has been added to the Threat Lookup Results tab. Possible values are: Malicious and Unknown.

* If an IoC lookup request does not find a security incident observable, it is labeled Unknown.
* If an IoC lookup request does find a security incident observable, it is labeled Malicious.

During an upgrade, existing items have the Finding column set to
Malicious.  
Note:  
While Threat Intelligence observables table data is part of a security incident, no other interaction with the Threat Intelligence module is included. For full threat functionality, the Threat Intelligence plugin is available by subscription.
**Related tasks**   

* [Create a security incident observable](https://servicenow-prod.fluidtopics.net/fPLnzEL94u1VuhKG8xqEtQ "You can create and view an observable within a security incident and take appropriate action. Having observables available in the security incident is scalable and reduces response time.")

