Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Get Observable Sightings Queries activity

The Get Observable Sightings Queries workflow activity retrieves queries from the integration configuration.

The Get Observable Sightings Queries activity can be used with any workflow to get queries to send to the specified implementation using the Parallel Flow Launcher.

Results

Possible results for this activity are:

ResultDescription
SuccessQueries found.
FailureAn error occurred while attempting to get queries. More error information is available in the activity output error.

Input variables

Input variables determine the initial behavior of the activity.

VariableDescription
observablesList of filtered observables.
capabilitiesList of supported capabilities.

Output variables

The output variables contain data that can be used in subsequent activities.

VariableDescription
queriesSearch string.
queryCountNumber of queries to run.

Parent Topic:Security Operations Integration - Sightings Search Flow