---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Explore

# Security Operations CrowdStrike Falcon Host - Publish to Watchlist Flow {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Security Operations CrowdStrike Falcon Host - Publish to Watchlist flow designer is used to specify the watchlist for generating alert or events. The alerts and events are displayed in the
CrowdStrike Falcon Host system based on how it is configured.

## Publish to Watchlist Flow {#secops-integration-crowdstrike-publish__context_swr_23s_fbb}

This flow designer is triggered by the [Security Operations Integration- Publish to Watchlist capability](https://servicenow-prod.fluidtopics.net/sqRJetgV_urJTWNWGVogFA "The Publish to Watchlist capability adds observables and indicators associated with a security incident to a third-party watchlist that monitors for security events and generates alerts. This capability is used as part of incident response during investigations.") when you select one or more observables associated with a security incident, and use the Publish to Watchlist UI action to push the observables to a watchlist. The observables can
then be used to generate additional alerts. For more information, see [Publish observables to a third-party watchlist](https://servicenow-prod.fluidtopics.net/3LD9kg9CZkcqBtZHRnbdjg "You can publish one or more observables or associated indicators to a third-party watchlist. Currently, the only implementation that supports this functionality is CrowdStrike Falcon Host.").

