Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create an observable from a case

New observables can be created from cases in Security Case Management.

Before you begin

Role required: sn_ti.case_user

Procedure

  1. Navigate to All > Threat Intelligence > Case Management > All Cases.

    The Security Cases list opens.

  2. Either open an existing case or click New to create a new case.

  3. Click the Case Artifacts related link and click the Observables tab.

  4. Click New and enter the requested information.

    FieldDescription
    Value[Read only] The case number.
    Observable typeEnter a descriptive name for the case.
    Observable type categorySelect the type of case being investigated.
    Incident countSelect the importance of this case (from Critical to Low).
    Finding[Read only] The date and time the case was last updated.
    NotesA brief description of the case.
  5. Click the Additional Case Details tab.

  6. Fill in the fields as appropriate.

    FieldDescription
    Created by[Read only] The name of the user who created this case.
    StateThe current state of the case. At case creation, the State defaults to Draft.
    Work notes listClick the check box to display the work notes in the Additional Case Details section of the case record.
    Work NotesIf needed, type a work note for the case. If the Work notes list is selected, the work note appears in the Additional Case Details section of the case record.
  7. Click Submit.

    As needed, you can click the Case Artifacts tab and add artifacts to the case.

Parent Topic:IoCs and observables in cases

Related topics

Create a case from IoCs or observables

Add IoCs and observables to an existing case

Run a sightings search on observables in a case