---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Deleting threat intelligence library records

# Deleting threat intelligence library records {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Delete threat intelligence library records such as observables, indicators, and objects.

## Before you begin

Role required: sn_sec_tisc.analyst

The following example procedure explains how to delete an observable record. You can use the same procedure to delete indicators or objects as well.

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security CenterThreat Intel LibraryObservablesAll Observables.
2. Open any observable record.
3. Select Delete to delete the aggregated record.  
   When you select this action, then it will remove all the related records, except the original source data, and trigger reaggregation.

   A confirmation message will appear to verify that you want to delete the
   aggregated record. If you also want to delete the source records and prevent re aggregation, select the Delete Source Records check box. This action will remove all the associated source
   records.
4. Select Delete.  
   The record will be deleted from threat intelligence library.

## What to do next

Refer to the section [Define an Observable](https://servicenow-prod.fluidtopics.net/30_u3Xt7vs~7zgdDpZkUmg "Observables can be retrieved from scheduled feed ingestion or from the import assistant. However, you can create observables, as needed.") to create a record.
**Related concepts**   

* [TISC Data Model](https://servicenow-prod.fluidtopics.net/IYhNIuDDe46ffpO552UcOA "The data model and architecture of threat intelligence security center module is designed to support threat intelligence platform capabilities and different security views that provides detailed data for threat analysts.")
* [TISC Library Objects form view](https://servicenow-prod.fluidtopics.net/wcpLnk6kmrmzTBQAPm2RxA "The Threat Intelligence Security Center objects home page consists of the following features.")
* [TISC Library Repository](https://servicenow-prod.fluidtopics.net/4G3NQv0L~ouF_cvQvhfm1w "IoC repository contains STIX objects, each of these objects contain a specific piece of information.")
* [Access Vulnerability Downstream actions](https://servicenow-prod.fluidtopics.net/T1aOjuKwsjuB9Hk2MCUSoQ "Access all downstream actions generated from a vulnerability record to track remediation progress and understand the scope of response activities.")
* [Automated Correlation](https://servicenow-prod.fluidtopics.net/iQ291vTNymOc8HLa54UzSw "Automated correlation helps you identify the relationships between observables, indicators, and objects.")  
**Related tasks**   

* [Export intelligence data](https://servicenow-prod.fluidtopics.net/w4RXvxKA~u3VcMYMpR4T9Q "Use the export feature to manually export the intelligence data in various formats.")
* [Confirm Potential Relationships from Related Records](https://servicenow-prod.fluidtopics.net/TQHhkN60eRr8MHck5BQqaw "Confirm the relationships between the two SDOs.")

*[\>]: and then


