---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Add a related IoC to an observable

# Add a related IoC to an observable {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

In addition to importing observables as STIX data, you can add related observables to
an IoC manually.

## Before you begin

Role required: sn_ti.admin

## Procedure

1. Navigate to AllThreat IntelligenceIoC RepositoryObservables.
2. Click the observable to which you want to add a related IoC.
3. Click the Related Indicators related list.
4. Click Edit.
5. As needed, use the filters to locate the indicator you want to relate with the observable.
6. Using the slushbucket, add the indicator to the Related Indicators list.
7. Click Save.
{#t_AddIoCToObserv__steps_kdz_krt_gv}
**Related tasks**   

* [Define an observable](https://servicenow-prod.fluidtopics.net/N_322_aca9GLw89huNJzWw "Observables are retrieved from the vendor server as STIX data. However, you can create observables, as needed.")
* [Add associated tasks to an observable](https://servicenow-prod.fluidtopics.net/VdG6~9jg_L2Cj_ubFik37Q "In addition to importing associated tasks (such as changes and incidents) as STIX data, you can add them to an observable manually.")
* [Add a related observable](https://servicenow-prod.fluidtopics.net/xLYwJX5KAfYux3reXTS2ow "In addition to importing observables as STIX data, you can add related observables manually.")
* [Load more IoC data](https://servicenow-prod.fluidtopics.net/n46mBDirxspECRSFrCeK5g "Depending on settings in two properties and a script include definition, you can load geolocation information for IP addresses and websites in the Observables form. With further customization, you can also add other information, such as country codes, city names.")
* [Identify observable sources](https://servicenow-prod.fluidtopics.net/Rsn_O9wAHfRweFF~mNIA1w "If an observable has no sources defined, it uses all types of sources. However, if you add one or more threat sources to an observable, it limits the sources used.")
* [Perform lookups on observables](https://servicenow-prod.fluidtopics.net/lpoUE~l5Cuui5Nt5XCnFsA "You can perform threat intelligence lookups on one or more observables to determine whether they’re associated with known security threats. The scanning implementations that run depend on the ones you’ve activated.")
* [Perform threat enrichment on observables](https://servicenow-prod.fluidtopics.net/gmFI_mpfWoTDtoNbzR72IA "You can perform threat intelligence enrichment on one or more observables to determine whether they’re associated with known security threats. The implementations that run depend on the ones you’ve activated.")

*[\>]: and then


