---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Export intelligence data

# Export intelligence data {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use the export feature to manually export the intelligence data in various formats.

## Before you begin

Role required: sn_sec_tisc.analyst

## About this task

Currently, the export functionality is limited to observables, indicators, and case management. The following procedure describes how you can export the observables data, and follow the same procedure to export the indicators
data.

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security CenterThreat Intel LibraryObservablesAll Observables.
2. Select any observable record.
3. Select Export.  
   Note:  
   The Export button is enabled only when observables are selected for export. If no observables are selected, the button remains disabled.
4. Select the desired file type for export.  
   * Currently, the supported export formats are Excel, CSV, and STIX 2.1 JSON. Suppose, if your export type is Excel then the number of records that can be exported at a time is limited to 10,000, regardless of the selected format type.
   * If the selection exceeds 10,000 records, then an error message displays indicating that the maximum limit for the selected format type has been surpassed, and only the first 10,000 records will be exported.
   * If the export format is CSV and the record limit is exceeded, an alert message is displayed indicating that the export is in progress state, along with a link to view the export status. You can click the link to view the status, and refresh the record. Once it moves to processed state you can download the attachment.  
     Note:  
     When you export records in STIX 2.1 format Traffic Light Protocol (TLP) definitions applied to the intelligence object are included in the export as TLP 2.0 marking definition objects. For more information, see [Define Marking Definition](https://servicenow-prod.fluidtopics.net/UhnWbf_woGr4oZrwiqa3kw "Define marking definitions to handle and share the requirements for the data.").
   {#tisc-export-observables__ul_lrl_3tc_m3c}
5. Select Export.  
   Note:  
   You can also view export data from the Imports/Exports module.  
   A confirmation message indicating that the export is successful and your download is complete displays.
**Related concepts**   

* [TISC Data Model](https://servicenow-prod.fluidtopics.net/IYhNIuDDe46ffpO552UcOA "The data model and architecture of threat intelligence security center module is designed to support threat intelligence platform capabilities and different security views that provides detailed data for threat analysts.")
* [TISC Library Objects form view](https://servicenow-prod.fluidtopics.net/wcpLnk6kmrmzTBQAPm2RxA "The Threat Intelligence Security Center objects home page consists of the following features.")
* [TISC Library Repository](https://servicenow-prod.fluidtopics.net/4G3NQv0L~ouF_cvQvhfm1w "IoC repository contains STIX objects, each of these objects contain a specific piece of information.")
* [Access Vulnerability Downstream actions](https://servicenow-prod.fluidtopics.net/T1aOjuKwsjuB9Hk2MCUSoQ "Access all downstream actions generated from a vulnerability record to track remediation progress and understand the scope of response activities.")
* [Automated Correlation](https://servicenow-prod.fluidtopics.net/iQ291vTNymOc8HLa54UzSw "Automated correlation helps you identify the relationships between observables, indicators, and objects.")  
**Related tasks**   

* [Deleting threat intelligence library records](https://servicenow-prod.fluidtopics.net/9h~3flpHUbUKTpRcxeekdA "Delete threat intelligence library records such as observables, indicators, and objects.")
* [Confirm Potential Relationships from Related Records](https://servicenow-prod.fluidtopics.net/TQHhkN60eRr8MHck5BQqaw "Confirm the relationships between the two SDOs.")

*[\>]: and then


