---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Add a related observable to an IoC

# Add a related observable to an IoC {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

In addition to importing observables as STIX data, you can add related observables to
an IoC manually.

## Before you begin

Role required: sn_ti.write

## Procedure

1. Navigate to AllThreat IntelligenceIoC RepositoryIndicators.
2. Click the indicator to which you want to add a related observable.
3. Click the Related Observables related list.
4. Click Edit.
5. As needed, use the filters to locate the observable you want to relate with the IoC.
6. Using the slushbucket, add the observable to the Related Observables list.
7. Click Save.
{#t_AddObservToIoC__steps_kdz_krt_gv}
**Related tasks**   

* [View an IoC](https://servicenow-prod.fluidtopics.net/~ASRrR0edM07oQ3MI4sOtw "IoCs, sometimes referred to as indicators, are most typically retrieved from a threat data source as STIX data. If needed, you can also create IoCs.")
* [Add a related attack mode/method to an IoC](https://servicenow-prod.fluidtopics.net/71yN6_imDcaKJra0hbuZzg "In addition to importing related attack modes/methods as STIX data, you can add related attack modes/methods to an IoC manually.")
* [Identify associated indicator types](https://servicenow-prod.fluidtopics.net/j7jI7NXQ5rkkVjy1BU_RQQ "If an IoC has no associated indicator types defined, it tracks all types of observables. However, if you associate one or more types of indicators to an IoC, it limits the types of observables that can be associated with the IoC.")
* [Identify indicator sources](https://servicenow-prod.fluidtopics.net/EMoDqbf3aJhgR5QQRJWTNA "Indicator sources are normally tracked automatically as part of the threat import process, but more sources can be manually added.")
* [Add associated tasks to an IoC](https://servicenow-prod.fluidtopics.net/aTdxtr6vXl9OPurAvip5Kw "In addition to importing associated tasks (such as changes and incidents) as STIX data, you can add them to an IoC manually.")

*[\>]: and then


