Skip to content
Release: Australia · Updated: 2026-07-09 · Official documentation · View source

Security annotations

A security annotation is a note of explanation or comments added to a configuration item, observable, or use on a security incident.

Multiple security annotations are available for users and observables (requires the Threat Intelligence plugin). Reports on security annotations are also available.

  • Create security annotations for CIs
    Annotations on CIs allow you to track activity across incidents. You can add annotations to a single or multiple CIs.
  • Create security annotations for observables
    You can select a single or multiple observables and apply security annotations to them using the Actions on selected rows choice menu.
  • Create security annotations for users
    You can select a single or multiple users and apply security annotations to them using the Actions on selected rows choice menu.
  • View security annotations reports
    The Security Annotations report presents details stored in the Security Annotations [sn_sec_cmn_security_annotations] table. You can customize the columns in the report and group the data in any way that suits you.

Parent Topic:Security Operations common functionality