Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Configure MISP sighting searches

Configure the ServiceNow AI Platform to do sighting searches for observables in the MISP instance. With this information, you can determine how often threats occur.

Before you begin

About this task

The Security Operations Integration - Sightings Search workflow executes the sighting searches. This workflow accepts a list of observables, finds any implementing capabilities, creates the queries that are based on the sighting search configurations, and executes the searches that are based on the configured workflow.

The MISP integration for Security Operations provides a base system sighting search profile that enables you to configure automatic sighting searches. With this profile, you can access the related observable sighting information of an organization and also see the external sightings from other organizations.

Procedure

  1. Navigate to All > MISP Integration > Sighting Search Configuration.

  2. Click New.

  3. On the form, fill in the fields.

    FieldDescription
    NameName for the capability profile.
    Is saved searchSearch configuration that is saved when you select this option. The saved search configuration queries are example queries. You can substitute them with the parameters for your environment and create additional saved search configurations as required.
    Sightings search sourceSource for the sightings search. Select the MISP log store as the source.
    ActiveOption that enables the saved search configuration. Only active search configurations can perform a sightings search.
    Observable typeObservable type such as the IP address, hash value, URL, and domain name.
    Maximum observable per searchMaximum number of observables that you can view from a search query.
    SearchDefault search string that is $(observable). However, you define your own search query by specifying the MISP log store supported parameters.
  4. Click Submit.

Result

You created a MISP sightings search configuration profile.

Parent Topic:MISP administration

Related topics

Getting started with MISP integration for Security Operations

Install and configure the MISP integration for Security Operations

Review the MISP integration settings

Configure how an automatic event is created

MISP event data

Associated MISP events

MISP user information

Domain separation and MISP

Troubleshooting MISP integration