---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Adding Timeline Events to the Canvas

# Adding Timeline Events to the Canvas {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Add timeline events to the investigation canvas by adding the related entities to the canvas.

## Before you begin

Role required: sn_sec_tisc.analyst

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security Center.
2. Select the Threat Analyst Workbench icon.
3. Go to Investigation CanvasesAll Canvases.
4. Select any canvas record.
5. Go to Investigation Canvas section on the selected canvas record.
6. Right click the desired node on the canvas, select Edit Timeline Event(s).  
   The Edit Timeline Event(s) dialog box displays.

7. Select Add Event to add the custom timeline event.
8. Select the Event and Timestamp of the event.
9. Select Save to confirm your changes to add a timeline event to the selected investigation canvas.  
   The event will be linked to the selected object and also include its timestamp. The visual presentation of the event including the icon and its color reflects the configuration defined during the setup.

   For
   information on how the timeline events are configured, see [Configure Custom Event Types for Timeline](https://servicenow-prod.fluidtopics.net/~flEdcwfzQzZUutKTphQrg "The Timeline component in the investigation canvas provides a chronological overview of all events related to a selected entity. This feature enables analysts to track actions, updates, and changes over time, offering a comprehensive historical perspective of the entity’s activity. As a result, it supports effective temporal threat analysis.").

*[\>]: and then


