---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Email Notifications

# Email Notifications {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use email notifications to send selected users email notifications about specific tasks within the application, such as updates to observables/indicators/various other objects.  
Role required: admin  
Note:  
As a System Administrator you can view, create or edit the email notification rule details in the classic view of the application.

Threat Intelligence Security Center provides rules driven email notifications which are sent to individual email addresses or a list of email addresses. Usually, Dissemination of Threat Intel information to internal
users are sent typically in the form of an email. The process involves in delivering the threat intelligence data to users according to their specified format and time lines.

Email notifications allow administrators to specify:

* When to send the notification
* Who receives the notification
* What content is in the notification

{#tisc-email-notifications__c_EmailNotifications_ul_gcf_1rp_54}  
Note:  
If you want to make changes, then you need to configure whom the email should be sent by modifying the base system rules based on your requirements.

For more information, see [Create an email notification](https://www.servicenow.com/docs/access?context=t_CreateANotification&version=australia&pubname=australia-platform-administration&ft:locale=en-US) section on ServiceNow AI Platform administration documentation.  
The following table details the email notification rules that are provisioned in the base system.{#tisc-email-notifications__table_jwn_zbj_cbc__entry__2}

| Name | Table |
|-|-|
| RSS Feeds with Zero Day mention | sn_sec_tisc_rss_feed |
| High Risk Malicious URL Observable | sn_sec_tisc_url |
| High Risk Malicious IPV6 Observable | sn_sec_tisc_ipv6_address |
| Threat Reports with Zero Day mention | sn_sec_tisc_threat_report |
| High Risk Malicious IPV4 Observable | sn_sec_tisc_ipv4_address |
| High Risk Malicious SHA512 Observable | sn_sec_tisc_sha512_hash |
| High Risk Malicious Domain Observable | sn_sec_tisc_domain_name |
| Notifying on case updation | sn_sec_tisc_case |
[Table 1. Email Notifications]

{#tisc-email-notifications__table_jwn_zbj_cbc}Figure 1. Email Notifications  
Note:  
Clicking on each email notification will take you to the classic UI, so that you can take necessary actions such as viewing or editing or creating the notifications.
**Related concepts**   

* [Email logs](https://servicenow-prod.fluidtopics.net/jCg3b21AWvu4_kGYsAdwOA "This section provides a clear visibility to the TISC administrators on the emails that are sent out using the configured email notification rules.")

