---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configuring Outbound Intel Sharing Profiles

# Configuring Outbound Intel Sharing Profiles {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Use this section to create new Outbound Intelligence Profiles. The outbound intelligence profiles specify the endpoint details to which threat intelligence data is sent.

## Before you begin

Role required: sn_sec_tisc.admin

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security CenterAdministrationOutbound Intel Sharing.
2. Select Outbound Intel Sharing Profiles.
3. Select New to create an Outbound Intelligence Profile.
4. On the form, fill in the fields.  
   {#tisc-outbound-sharing-profiles__table_syl_ztc_mfc__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the outbound intelligence profile. |
   | Industry | Select the industry category such as Aerospace, Agriculture for which the outbound intelligence profile is applicable to. |
   | Description | Description of the outbound intelligence profile. |
   | Outbound Intelligence Settings ||
   | Data Format | Supported data formats for outbound intelligence sharing profile. Currently, the following two data formats are supported for outbound intelligence sharing: * STIX 2.1: Supports various endpoint types, including basic authentication endpoints and open-source endpoints. To accommodate this, two authentication types are available for STIX 2.1. * MISP: For MISP, authentication is handled exclusively through an API key. * When MISP is selected as the format, the Authentication Required option is automatically enabled. * The authentication type is fixed as API Key, and users must provide a valid API key to connect to the MISP instance. {#tisc-outbound-sharing-profiles__ul_vbl_qbd_mfc} {#tisc-outbound-sharing-profiles__ul_v12_h1d_mfc} |
   | API Endpoint URL | Enter the API endpoint URL to which the data needs to be sent. |
   | Authentication Required | Select this check box if the authentication is required. |
   | Authentication Type | Select the required option from the drop down list if the authentication is required. The available option is: Basic: Select this option to provide user name and password. |
   | Headers to be passed with request | Any headers to be passed with the requests can be provided for the outbound intelligence profile. Header should be provided in key-value pair separated by colon(':'). Each header key value pair should be provided in a new line. For providing authentication parameters as header values, enclose the required authentication with '${' and '}$'. (for example : username:${Username}$) |
   [Table 1. Create New Outbound Intelligence Profile]

   {#tisc-outbound-sharing-profiles__table_syl_ztc_mfc}
5. Once the profile and authentication details are provided, click Save.
6. Select Validate Connection to confirm the setup by testing the endpoint URL configured under Intelligence Outbound Sharing.  
   This option enables you to provide a request body to validate the specific endpoint defined in the profile section.  
   Note:  
   A sample request body is displayed based on the selected format, and you can modify it as needed.

   Make the necessary changes to the request body and click Save and Validate button. In case if you want to reset to the original sample request body then you can select
   Reset button to reset it back to the original request body.

   A confirmation message is displayed indicating that the connection to endpoint is successful.

   If the connection to the endpoint is not successful, then check the error logs and resolve any issues before retrying.
7. Select the Enable button to enable the outbound intelligence sharing profile.  
   Note:  
   When you select Enable button, then the validation to the end point checks occur automatically.
   Whenever you create a sharing profile, Enable button appears only when the connection is successfully validated otherwise this button will not be visible until the connection to the endpoint is successful.  
   A confirmation message is displayed indicating the sharing profile is successfully enabled.  
   Note:  
   You must enable the sharing profile to use it for sharing intelligence.
8. Additionally, select Disable to disable the profile if it is not needed for sharing intelligence.
**Related tasks**   

* [Configuring Outbound Intel Sharing Controls](https://servicenow-prod.fluidtopics.net/1hZHuAm0zEGADdPfUVXaIg "Use this section to configure outbound sharing controls, which determine the entities enabled for intelligence sharing from TISC to external systems.")
* [Configuring Outbound Intel Data Exclusion Rule](https://servicenow-prod.fluidtopics.net/2d0fdgmQ6bqkYGvIbuuyug "Use this section to create exclusion rules, which can be configured by TISC admin to restrict sharing of records that match the defined criteria.")
* [Configuring Outbound Intel Sharing Groups](https://servicenow-prod.fluidtopics.net/991t1csl9sSEPta9MtviDg "Outbound Intel Sharing Groups allow you to combine multiple profiles and use them collectively when sharing data.")
* [Defining Approval Rule for Outbound Intel](https://servicenow-prod.fluidtopics.net/tBYkoIRyd~7SM0oHgw4MMw "Define approval rules to control whether certain users require approval before sharing the shared intelligence.")
* [Configuring Outbound Intel Sharing Templates](https://servicenow-prod.fluidtopics.net/160U6adHmYOxO_VAdpfWAA "Outbound Intel Sharing Templates enable you to define and control the data shared externally from the Threat Intelligence Security Center (TISC).")
* [Working on the Redaction Library](https://servicenow-prod.fluidtopics.net/I2Fnhq550Id7apaHgnUDHw "Redaction is the process of replacing sensitive information from shared data to protect confidentiality during intelligence sharing.")

*[\>]: and then


