Add multiple security incident observables
To save time, you can add multiple security incident observables to the security incident observables list.
Before you begin
Role required: sn_ti_write
Note: When adding multiple security incident observables, duplicates are ignored during processing.
Procedure
Navigate to Security Incident.
Choose an incident.
Select the Investigation tab.
Select Associated Observables.
Select Multiple New from the more options.
Enter or paste multiple observables.
Entries can be of any Observable Type. Accepted formats are: comma, new line, tab, or pipe separators.
Image omitted: AddMultipleObservables.png
Add multiple observables comma delimited list example
Add multiple observables comma delimited list example
**Note:** When you add an observable to the security incident, the system checks for any other configuration items or users associated with it. The **Related Configuration Items** and **Related Users** related list tabs are updated accordingly.
Note: Observable values not auto-detected are assigned to type Unknown.
- Select Submit.