---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create TAXII Collection

# Create TAXII Collection {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Use this section to learn how to configure and define TAXII collections for sharing intelligence.

## Before you begin

Role required: sn_sec_tisc.admin

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security CenterAdministrationTAXII Outbound Server.
2. Select TAXII Collections.
3. Select New to create a TAXII Collection.
4. On the form, fill in the fields.  
   {#tisc-create-taxii-collection__table_syl_ztc_mfc__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the TAXII collection. |
   | Description | Description of the TAXII collection. |
   | Spec Version | Specifies the version of the TAXII used for data formatting and exchange. Note: The only supported spec version for data formatting is 2.1. |
   | Expiry period (days) | Specifies the number of days after which the records added to the TAXII Collection expires. Note: After expiration, the records will be marked as inactive and subsequently removed from the collection. |
   | Enable Versioning | Select this check box to enable versioning for the records being added to the TAXII collection. Note: When a record is added to a TAXII collection and if it differs from its previous version, the application will add the new version only if the versioning is enabled. If the versioning is not enabled, the existing record will be overwritten with the updated data. |
   | Access to all TAXII API users | Specifies access for TAXII users. When selected, all users assigned the TAXII Server API role will be granted permission to retrieve data from this collection. Note: When the Access to all TAXII API users field is not selected, only the users specified in this field will have access to the TAXII collection records. |
   | Read Access | When the Access to all TAXII API users field is not selected, then only the users specified in this field will be able to access the TAXII collection records. |
   [Table 1. Create Inbound Intelligence Profile]

   {#tisc-create-taxii-collection__table_syl_ztc_mfc}
5. **Optional:** To copy the discovery URL of the TAXII server, do the following:
   1. Select the information icon on the record to open TAXII Server Configuration.
   2. Select the copy icon next to the Discovery URL field.  
      The discovery URL is copied to your clipboard. Share this URL with TAXII clients to connect to your instance and retrieve the threat intelligence shared through the TAXII collection.
   {#tisc-create-taxii-collection__substeps_glx_3pt_rjc}
6. Select Save.

System property to add records

The system property for TAXII collections limits the number of records that can be added to a TAXII collection.

The following is the system property for
the TAXII Collection configuration:
{#tisc-create-taxii-collection__table_rzw_ds3_4fc__entry__2}

| Name | Description |
|-|-|
| sn_sec_tisc.taxii_server_collection_record_limit | Maximum number of records that can be added to an outbound TAXII server collection. The default value is 10000. |
[ ]

{#tisc-create-taxii-collection__table_rzw_ds3_4fc}

7. View the system property information for adding records to the TAXII collection.
8. Navigate to the Flow DesignerFlows.  
   This navigation displays the template flow for adding TAXII Collections.
9. Select the Automatically add threat intelligence to a TAXII Collection flow.
10. Navigate to the Flow DesignerActions.

Adding records to the TAXII Collection  
Currently, the only method for adding records to the TAXII server collection is via an automated process. The following are the two actions that are provisioned in the base system:

1. Add Record to TAXII Server Collection
2. Add Records to TAXII Server Collection
{#tisc-create-taxii-collection__ol_tfg_gqn_pfc}

11. View the respective TAXII server collection action.
**Related tasks**   

* [Automated Sharing of TAXII Collections](https://servicenow-prod.fluidtopics.net/bInKcF1OgZu6a7O~1gDEGQ "Automated TAXII Collections automatically add intelligence records to TAXII Server Collections for seamless distribution to trusted external partners.")
* [Viewing TAXII Collection Records](https://servicenow-prod.fluidtopics.net/oQzlvHN5p1DSVRlLBpct~g "View the records that are added to the TAXII collections.")
* [Automated Sharing of TAXII Collections](https://servicenow-prod.fluidtopics.net/bInKcF1OgZu6a7O~1gDEGQ "Automated TAXII Collections automatically add intelligence records to TAXII Server Collections for seamless distribution to trusted external partners.")
* [Configuring Outbound Intel Sharing Templates](https://servicenow-prod.fluidtopics.net/160U6adHmYOxO_VAdpfWAA "Outbound Intel Sharing Templates enable you to define and control the data shared externally from the Threat Intelligence Security Center (TISC).")

*[\>]: and then


