---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# SIR Workspace Related Records

# SIR Workspace Related Records {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 7 minutes to read

This section consists of the related lists items that are grouped into sections such as associated observables and configuration items.

The following related lists groups that are available as a part of the base system. You can modify these groups or create groups within the application and their respective actions.  
You can modify these groups or create new groups. For more information, see [Configure Security Incident Related List](https://servicenow-prod.fluidtopics.net/gsDO~PbQk8zzmwnZXCwg6Q#configure-analyst-workspace-related-lists "You can add new related lists or new related list groups, and modify existing groups or related lists that appear in the SIR Workspace.") on how to configure and group the related list for security incidents and response tasks. Each related list is fully functional within the SIR Workspace. {#sir-records__table_dyj_zqv_x5b__entry__2}

| Related list | Grouped item |
|-|-|
| Business Impact | * Configuration Items * Affected Users * Related Configuration Items * Related Users * Affected Services {#sir-records__ul_rsr_brv_x5b} |
| Threat Intel | * Associated Observables * Threat Lookup Results {#sir-records__ul_pp4_ngx_hxb} |
| Phishing | * Associated Phish Emails * Associated Phish Headers {#sir-records__ul_tsj_hrv_x5b} |
| Related Security Incidents | * Parent Security Incident * Child Security Incident * Similar Security Incident {#sir-records__ul_lkb_krv_x5b} |
| SLA Records | Task SLAs |
| Source Events/Alerts | Source events or alerts are the SIEM integration enabled related list such as Source Email, LogRhythm Drill Down Logs, LogRhythm Events, Aggregated IBM QRadar Offense and so on. Note: This list is completely dependent on the integration that you have in your instance. To view the relevant SIEM integration related list, you must install the latest version. |
| Sighting Search | * Sightings Search Results * Sightings Search Details * Sighting {#sir-records__ul_kpk_sqp_fzb} |
| Observable Enrichment | * Observable Enrichment Results * Associated MISP Events * MISP Enrichment Results {#sir-records__ul_dmh_vqp_fzb} |
| Endpoint Detection and Response (EDR) | * Host Details * Running Processes * Running Services * Logged On Users * Network Statistics * Get File * Isolate Host Entries * Additional Actions On Endpoint * Microsoft Defender for Endpoint-Related Machines Details {#sir-records__ul_iyh_crp_fzb} |
[ ]

{#sir-records__table_dyj_zqv_x5b}  
Note:  
In general, you'd be able to create new records, link, or unlink existing records or new records against the related list group as applicable.
**Related concepts**   

* [Set up view of SIR Records](https://servicenow-prod.fluidtopics.net/p99YPRJHUz3SrQBoAXW8UA "This section describes how the related lists are grouped and presented on the SIR Related Records tab for easy navigation.")
* [Configure SI design time investigation](https://servicenow-prod.fluidtopics.net/KsFsXg8CHBvaYTkUnuEOpQ "Use this section to configure security incident design time investigation page to add multiple entry points and its associated records within the Security Incident Response Workspace.")
* [Configure Shift Handover](https://servicenow-prod.fluidtopics.net/Q04QzNU1caN3mjs4rEUNGg "Configure Shift Handover settings to provide complete shift information to the next shift analysts.")
* [Security Incident Response conference call integration](https://servicenow-prod.fluidtopics.net/88P4jTtlgisR6XEYl1fsMA "The Security Incident Response Conference Call integration enables you to manage and initiate conference call and chat for analysts, managers and affected users.")
* [Configure report templates in Security Incident Response](https://servicenow-prod.fluidtopics.net/VKFCEyFnJHSOxoVttZW0gg "You can create report templates that can be used to generate an incident summary or an executive summary for analysis and sharing.")
* [On-Call scheduling in Security Incident Response](https://servicenow-prod.fluidtopics.net/sPKhH7CGbUOINSD8C3fVaQ "Use On-Call Scheduling in Security Incident Response to view and manage shifts for your analysts.")
* [Category management in Security Incident Response](https://servicenow-prod.fluidtopics.net/zKvvJ~woONAARtQWDnLzkQ "Configure security incident categories and subcategories for granular classification of incidents, which helps you accurately route security incidents.")
* [View and update Security Incident Response system properties](https://servicenow-prod.fluidtopics.net/dQgedytB1~M7u70FoX9_oA "View and update the Security Incident Response Workspace system properties from the Security Incident Response Workspace administration panel to access and update the required properties.")
* [Timeline in Security Incident Response Workspace](https://servicenow-prod.fluidtopics.net/U3c3lwBFolisJEn2MEJSmg "The timeline provides a chronological view of events related to a security incident. Events appear as point events or range events. Administrators can configure which events appear on the timeline and what details are shown in event popovers.")  
**Related tasks**   

* [Define the new Risk Score Calculator Rules](https://servicenow-prod.fluidtopics.net/ccv9hx8vlS4KWyZ44meslQ "Use the new Risk Score Calculator to define and calculate the risk score of security incidents based on the user-defined criteria, which provide a transparent intelligence scoring of security incidents. The risk score is auto-calculated for the security incident records.")
* [Create quick filters for Security Incidents and Response Tasks lists](https://servicenow-prod.fluidtopics.net/SzkWp6I2kcU8DCTa3RrrTw "Create quick filters to create reusable, predefined filters that appear on the security incidents and response tasks list pages enabling security analysts to filter the list items without adding the filter conditions each time.")
* [Configure Security Incident Related List](https://servicenow-prod.fluidtopics.net/gsDO~PbQk8zzmwnZXCwg6Q#configure-analyst-workspace-related-lists "You can add new related lists or new related list groups, and modify existing groups or related lists that appear in the SIR Workspace.")

## Configure Security Incident Related List {#ariaid-title2}

You can add new related lists or new related list groups, and modify existing groups
or related lists that appear in the SIR Workspace.

### Before you begin

The security incident related list are grouped and displayed as group related list
items on the Related Records tab on the workspace.

Role required: sn_si.admin

### Procedure

1. In the classic UI, navigate to AllSecurity IncidentShow Open Incidents.  
2. Select any incident record.
3. Right click on the incident context menu.
4. Go to ConfigureRelated List.  
   The Configuring related lists on Security Incident form is displayed.
5. Go to View name and select New.
6. Enter a name for the view.
7. Select the newly created view.  
   After you select the view, choose the required related list fields from the slush bucket.

   Note:  
   If you want to modify anything, select the view and remove or add the items.
8. Click Save.
9. On the left navigation, navigate to AllNow Experience FrameworkExperiences.
10. Select Security Incident Response Workspace.  
    The UX Application Security Incident Response Workspace page is displayed.
11. Go to UX Page Properties tab and select relatedListLayoutConfig option in the list view.  
12. Add the newly created view name separated by a comma to an already existing list of values in the Value text box under the sn_si_incident.viewsUsedForGrouping field.  
    For example, if you had created a new view name as, Business Impact then in the Value text box you must specify it as business_impact (which is separated by underscore within the view name and separated by a comma after an existing value) under the sn_si_incident:groups field.


    Note:  
    If you add the new view name under sn_si_incident.viewsUsedForGrouping field then the entry will be created in the Related Records tab of the workspace.

    If you update
    the view name entry in si_other_records.viewsUsedForGrouping then the related list group will get added in the Other Records tab of the workspace.
    Below is an example view which shows the newly created views added.  
    Note:  
    requiredRolesForGrouping contains comma separated sys_user_role record names. SIR Workspace user should have at least one of these roles, to use the grouped related lists. When a user does not have any of these roles then related lists view configured for the current user role using view rule configuration will be represented vertically without grouping. This property is ignored when isGrouped property is set to false. If this property is empty any user can access the grouped related lists.
13. Click Save.
14. Navigate to WorkspacesSecurity Incident Response Workspace.
15. Select any specific security incident.
16. Go to Related Records tab of the workspace.  
    The grouped related lists are displayed.

## Configure Response Task Related List {#ariaid-title3}

Use this section to configure response tasks new related lists that appears on the
Security Incident Response application.

### Before you begin

Role required: sn_si.admin

### About this task

The response tasks related list is not grouped but displayed as individual related list items, as there are few default lists. View the response tasks related items from the Response Tasks tab of the
security incident record of the workspace.

### Procedure

1. Navigate to AllSecurity IncidentResponse TasksShow All Tasks.  
2. Select any response task record.
3. Select and hold (or right-click) the Security Incident Response Task context menu.
4. Navigate to ConfigureRelated List.  
   The Configuring related lists on Security Response Task form is displayed.
5. Go to View name and select sirw view.  
6. Select the desired related list fields from the slush bucket.  
   For example, Affected Locations.
7. Select Save.
8. Navigate to WorkspacesSecurity Incident Response WorkspaceResponse Tasks.  
   The configured related lists (For example, Affected Users as selected) is listed within the Related Records list.
{#configure-response-task-related-list__steps_dxn_k2p_55b}

*[\>]: and then


