---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# View Sightings Search Results

# View Sightings Search Results {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can review Sightings Search Results for internal and external malicious
indicators.

## Before you begin

Role required: sn_si.analyst

## About this task

.

## Procedure

1. Navigate to a security incident.
2. Select the Sightings Search Results tab from Show IoC Related List group to view the list of sightings searches.  
   Note:  
   This data can be shared with Trusted Security Circle.  
   {#view-sightings-search-results__table_lg3_dm5_vy__entry__2}

   | Result | Description |
   |-|-|
   | Number | Sightings Search identifier. |
   | Observable count | Number of observables searched for. |
   | Internal Sightings | Aggregated count of internal sightings. |
   | External Sightings | Aggregated count of external sightings. (Received from threat sharing.) |
   | Matched configuration items | Aggregated count of configuration items that matched an existing record in your `cmdb`. |
   | Start date range | Time to start looking for sightings. |
   | End date range | Time to stop looking for sightings. |
   | Updated | Date and time of last modification. |
   [Table 1. Sightings Search Results]

   {#view-sightings-search-results__table_lg3_dm5_vy}

   To view the details of a single search:
3. Select a Sightings Search reult in the Sightings Search Results list.  
   The Sightings Search Result form displays. {#view-sightings-search-results__table_hsf_k1f_gz__entry__2}

   | Detail | Description |
   |-|-|
   | Number | Internal Sightings Search identifier. |
   | Observable count | Count of observables searched for by this query. |
   | Internal sightings | Count of internal sightings for this search. |
   | External sightings | Count of external sightings for this search. (Received from Trusted Security Circle.) |
   | Unmatched hosts | List of potential configuration items for this search that were not matched with any records in your `cmdb`. |
   | Task | Security incident task identifier. |
   | Start date range | Time the sightings search started. |
   | End date range | Time the sightings search stopped. |
   | Updated | Date and time of last modification. |
   | Sightings Search Details | Type, number of sightings and modification date. |
   | Matched Configuration Items | Count of configuration items that matched an existing record in your `cmdb`. Lists the CI and the Sighting. |
   | Threat Shares | List of the threats shared with Trusted Security Circle. |
   [Table 2. Sightings Search Results form]

   {#view-sightings-search-results__table_hsf_k1f_gz}
{#view-sightings-search-results__steps_otk_wsf_gz}
* **[Share Sightings Search results](https://servicenow-prod.fluidtopics.net/dTfq4f7XbiRwuUn7eZxvLQ)**   
  You can share local sightings details or results that are associated with a particular search with your Trusted Security Circle.
* **[Share observables from a security incident](https://servicenow-prod.fluidtopics.net/~6mwEpvHYj7EX48FUdmaTg)**   
  Observables can be shared from a security incident in Security Incident Response to members in your trusted circle.

