Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Sightings Search - Determine Observables activity

The Sightings Search - Determine Observables workflow activity determines which observables to include in the workflow.

The Sightings Search - Determine Observables activity can be used with any workflow to determine which observables to include in the workflow.

Results

Possible results for this activity are:

ResultDescription
SuccessFound observables
FailureNo observables found. More error information is available in the activity output error.

Input variables

Input variables determine the initial behavior of the activity.

VariableDescription
task_sys_idTask identifier (maps security incident to observables).
observablesIP addresses, hash, URLs, domain names.
workflow_current_sys_idSystem identifier of the current record. (Used only if task_sys_id, observable inputs are not available).

Output variables

The output variables contain data that can be used in subsequent activities.

VariableDescription
observablesFiltered observables

Parent Topic:Security Operations Integration - Sightings Search Flow