---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Send Observables to TISC

# Send Observables to TISC {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Using this feature the security analyst can push the observables data from SIR to TISC. Using the TISC Context, you can check if the observables are present in TISC, if not security analyst can push the data whenever
required.

## Before you begin

Role required: sn_si.analyst

## Procedure

1. Navigate to WorkspacesSecurity Incident Response WorkspaceSecurity IncidentsAll.
2. Open a security incident.
3. Select the Related Records tab to perform the TISC integration capability action.  
   Note:  
   * You can also navigate to the Investigation tab, and navigate to the Entry Points Lists section displayed on the left side of the page and select Associated Observables to perform the push operation.
   * On the Investigation tab, select View Related Info to view all the associated threat lookup, sighting search, and enrichment data for the selected observable. For more information, see [Explore Investigation Canvas](https://servicenow-prod.fluidtopics.net/3Mx~XCZXw7LsX0QFKRP_eg "The primary objective of the investigation canvas is to present the necessary security incident data in one common place.").
   {#tisc-context-in-sir-workspace__ul_g25_xlb_h1c}
4. For example, select Threat IntelAssociated Observables to perform the push operation and manually push the data into TISC.
5. Select one or more observable record to perform Send Observable to TISC operation to push the data.  
6. Select Send Observable to TISC.
7. On the Send Observables to TISC screen, provide the following:  
   {#tisc-context-in-sir-workspace__table_apk_fvz_zfc__entry__2}

   | Field | Description |
   |-|-|
   | Confidence | The confidence score for the observables. |
   | TLP | The TLP (Traffic Light Protocol) value for the observables. |
   | Notes | Notes for the observables. |
   | TISC Tags | Tags for the observables to send. You can add custom tags that are added to the observables. |
   [Table 1. Add information to TISC observables]

   {#tisc-context-in-sir-workspace__table_apk_fvz_zfc}
8. Select Send.  
   Note:  
   * If the selected observable isn't present in TISC, then first the observable will be created as observable source and then once source observable creates TISC observable record, the observable record will be automatically associated with the newly created observable.
   * Once the observable push operation is performed, then an information message is displayed.

     ```
     Following observables are successfully pushed to TISC. 
     It may take sometime to reflect in TISC context tab. 
     0.0.0.0
     ```

   * If an observable already exists TISC, then an error message is displayed.

     ```
     The following observables already exist in TISC:
     0.0.0.0
     ```

   {#tisc-context-in-sir-workspace__ul_btm_54b_h1c}
9. Select TISC Context.  
   Note:  
   :
   * You will now see the observable that is pushed to TISC from SIR application.
   * In a manual push operation: The observable data can only be pushed if they are linked to the security incidents. Once the observable is pushed from SIR then that data can be identified using sources which will have reference to security incident linked to the observable.
   * In an automatic push operation: The observable or enrichment data will be pushed automatically when it is associated to security incident.  
     Note:  
     The Send Observable to TISC option disappears once the automated flow is enabled.
   * TISC Context shows all the SIR associated observable which are also present in TISC.
   * Using TISC context, the SIR analysts can see all the TISC Enrichment data including Threat Lookups, Sighting Search, and Observable Enrichment Results.
   * View Associated Info will show all the associated observable enrichment data of the selected observables.
   {#tisc-context-in-sir-workspace__ul_a1g_vqb_h1c}
10. View the results.
**Related tasks**   

* [Add security incident to TISC case](https://servicenow-prod.fluidtopics.net/oRyoXHXc6vM0yC1H_dAqDQ "Add security incidents to TISC case records.")
* [Add observables to TISC Case](https://servicenow-prod.fluidtopics.net/6hTKrR7dtiA2DUf~bV0JXQ "Add observables to TISC case records.")
* [Send Threat Lookup to TISC](https://servicenow-prod.fluidtopics.net/QQdzzepm419PH_VxjzMw9w "Using this feature the security analyst can push the threat lookup data from SIR to TISC. Using the TISC Context, you can check if the threat lookup results are present in TISC, if not security analyst can push the data whenever required.")
* [Send Sighting Search to TISC](https://servicenow-prod.fluidtopics.net/lrH4qlEmdq1zowWEOb~Cbw "Using this feature the security analyst can push the sighting search data from SIR to TISC. Using the TISC Context, the analyst can check if the sighting search data is present in TISC, if not the security analyst can push the data whenever required.")
* [Send Observable Enrichment to TISC](https://servicenow-prod.fluidtopics.net/d_zRa7QF_uxPqTH8ByInUg "Using this feature the security analyst can push the sighting search data from SIR to TISC. Using the TISC Context, the analyst can check if the sighting search data is present in TISC, if not the security analyst can push the data whenever required.")  
**Related reference**   

* [System properties to send data](https://servicenow-prod.fluidtopics.net/xQZzhDOp9JP7rBFciK40Ow "Review the system properties for TISC integrations to combine with SIRW. You can configure these properties to control how both applications manages the integrations.")

*[\>]: and then


