---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Share observables from a security incident

# Share observables from a security incident {#ariaid-title1}

* Release version: Australia
* 
* Updated August 11, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Observables can be shared from a security incident in Security Incident Response to members in
your trusted circle.

## Before you begin

Role required: sn_si.analyst

## Procedure

1. Navigate to a security incident.
2. Select the Observables tab from Show IoC Related List group.
3. Select an observable.
4. On the Observable form, select the Share observable related link.  
   The Observable Share dialog box appears.
5. Enter a Name for this threat share record.
6. Enter a Description of the selected observables.
7. Choose Circles to share the observables with.
8. Select Submit.  
   The observable(s) are shared with the specified Trusted Circle.
9. You can view the threat share records by selecting the Threat shares tab.
10. If any of the shared observables contain sightings, the sightings are also shared and can be viewed by selecting the Sightings tab.
{#share-observable__steps_otk_wsf_gz}

