---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Define an observable

# Define an observable {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Observables are retrieved from the vendor server as STIX data. However, you can
create observables, as needed.

## Before you begin

Role required: sn_ti.admin

## Procedure

1. Navigate to AllThreat IntelligenceIoC RepositoryObservables.
2. Click New.  
3. Fill in the fields on the form, as appropriate.  
   {#t_AddObservable__table_hsg_w5w_yt__entry__2}

   | Field | Description |
   |-|-|
   | Select classification tag | If you set up and activated [security tags](https://servicenow-prod.fluidtopics.net/bus9vK7pliypx82WYkj9OQ "You can assign tags to security incidents, response tasks, vulnerable items, observables, IoCs, and security cases to create metadata on the responding record and define who should have access to specific types of security content. The tags can be added to security groups to organize them.") to add metadata to the record, you can select one or more tags to specify the degree of sensitivity of the observable. If you did not set up or activate security tags, this drop-down list is not displayed. |
   | Value | The value (for example, IP address or hash) associated with the observable. Note: If a threat scan on an IP address or hash, returned malware or some other failure, the IP address or hash value is automatically added to the Observable \[sn_ti_observable\] table. As such, it can be searched for from the Observables form. |
   | Observable type | Select the observable classification, such as an IP address or file hash. These observable types are defined in the Observable Types module. |
   | Incident count | The number of times the observable value has been encountered. |
   | Is composition | This field displays only after the observable record has been saved. If the Observable Type is set to anything other that Observable Composition, and this new observable is a composition, select this check box. If the Observable Type is already set to Observable Composition, the check box is selected and read-only. An observable composition is an observable that contains child observables. |
   | Finding | Select one of the following: * Malicious: Indicates that the observable is harmful to the organization. * Suspicious: Indicates that the observable might be harmful to the organization. * Clean: Indicates that the observable is not harmful to the organization. * Unknown: Indicates that we are yet to determine the observable's finding. * Default value: Unknown. For more information, see [Threat Lookup Finding Calculators](https://servicenow-prod.fluidtopics.net/PZ2IhdAw~x~KTkf~u8noxA "Threat Lookup Finding Calculator helps you calculate the observable findings based on the responses received."). {#t_AddObservable__ul_rzd_ldd_3vb} Note: After an upgrade, existing observables are marked Malicious. |
   | Operator | This field appears only when the Is composition check box is selected. Depending on your setting in this field, the observables and their children are considered when deciding whether an associated indicator is present. Set this field to AND if all the child observables must be present for an associated indicator to be considered present. Set it to OR if any of the child observables are present for an associated indicator to be considered present. |
   | Must not be present | This field displays only after the observable record has been saved. If selected, this field signifies that the absence of the observable is the potential issue (for example, a missing registry key). |
   | Location | Using the settings in two properties and a script include definition, you can load [Load more IoC data](https://servicenow-prod.fluidtopics.net/n46mBDirxspECRSFrCeK5g "Depending on settings in two properties and a script include definition, you can load geolocation information for IP addresses and websites in the Observables form. With further customization, you can also add other information, such as country codes, city names.") in this field. |
   | Notes | Enter any additional notes about the observable. |
   [ ]

   {#t_AddObservable__table_hsg_w5w_yt}
4. Right-click in the form header and click Save.  
   You can now click any of the following related lists to view additional information.  
   {#t_AddObservable__table_bmj_3ky_fv__entry__2}

   | Related List | Description |
   |-|-|
   | Related Indicators | Lists indicators that have been identified by the threat source. |
   | Associated Tasks | Lists changes associated with the observable. |
   | Child Observables | Lists related observables that have been identified by the threat source. |
   | Matching Resources for IP | If the observable is an IP address, this list shows any resources (configuration items) that have a matching IP address. |
   | Observable Sources | Lists the sources of this observable, along with the confidence level of the source. |
   | Security Annotations | Lists security annotations added to this observable. |
   [ ]

   {#t_AddObservable__table_bmj_3ky_fv}
{#t_AddObservable__steps_vyt_hjd_gv}
**Related tasks**   

* [Add a related IoC to an observable](https://servicenow-prod.fluidtopics.net/7HtyAyberW_1wRBwjHGytg "In addition to importing observables as STIX data, you can add related observables to an IoC manually.")
* [Add associated tasks to an observable](https://servicenow-prod.fluidtopics.net/VdG6~9jg_L2Cj_ubFik37Q "In addition to importing associated tasks (such as changes and incidents) as STIX data, you can add them to an observable manually.")
* [Add a related observable](https://servicenow-prod.fluidtopics.net/xLYwJX5KAfYux3reXTS2ow "In addition to importing observables as STIX data, you can add related observables manually.")
* [Load more IoC data](https://servicenow-prod.fluidtopics.net/n46mBDirxspECRSFrCeK5g "Depending on settings in two properties and a script include definition, you can load geolocation information for IP addresses and websites in the Observables form. With further customization, you can also add other information, such as country codes, city names.")
* [Identify observable sources](https://servicenow-prod.fluidtopics.net/Rsn_O9wAHfRweFF~mNIA1w "If an observable has no sources defined, it uses all types of sources. However, if you add one or more threat sources to an observable, it limits the sources used.")
* [Perform lookups on observables](https://servicenow-prod.fluidtopics.net/lpoUE~l5Cuui5Nt5XCnFsA "You can perform threat intelligence lookups on one or more observables to determine whether they’re associated with known security threats. The scanning implementations that run depend on the ones you’ve activated.")
* [Perform threat enrichment on observables](https://servicenow-prod.fluidtopics.net/gmFI_mpfWoTDtoNbzR72IA "You can perform threat intelligence enrichment on one or more observables to determine whether they’re associated with known security threats. The implementations that run depend on the ones you’ve activated.")

*[\>]: and then


