Configure Sighting Search
Configure sighting search integration to search your organization logs for one or more observables to determine how many times each observable appears, within a specified date range or number of days.
Before you begin
Important:
The enrichment integrations appears only if at least one enrichment integration is installed and active.
The Threat Intelligence Security Center supports Sightings Search for the following integrations only:
- Splunk Search
- Elasticsearch
Role required: sn_sec_tisc.admin
Note:
The Sightings Search section lists integrations of the Sightings Search type. Each configured integration appears as a card, which you can enable or disable.