Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create a security incident observable

You can create and view an observable within a security incident and take appropriate action. Having observables available in the security incident is scalable and reduces response time.

Before you begin

Role required:

  • sn_ti_observable.write (write)
  • sn_ti_observable.read (read)
  • sn_ti_observable.admin (delete)

Procedure

  1. Navigate to Security Incident.

  2. Choose an incident.

  3. Select the Security Incident Observables related list tab.

  4. Select New.

  5. Fill in the fields on the form, as appropriate.

FieldDescription
Select classification tagIf you set up and activated security tags to add metadata to the record, you can select one or more tags to specify the degree of sensitivity of the observable. If you did not set up or activate security tags, this drop-down list is not displayed.
ValueThe value (for example, IP address or hash) associated with the observable.Note: If a threat scan on an IP address or hash, returned malware or some other failure, the IP address or hash value is automatically added to the Observable [sn_ti_observable] table. As such, it can be searched for from the Observables form.
Observable typeSelect the observable classification, such as an IP address or file hash. These observable types are defined in the Observable Types module.
Incident countThe number of times the observable value has been encountered.
Is composition

This field displays only after the observable record has been saved.If the Observable Type is set to anything other that Observable Composition, and this new observable is a composition, select this check box.

If the Observable Type is already set to Observable Composition, the check box is selected and read-only.

An observable composition is an observable that contains child observables.

Finding

Select one of the following:- Malicious: Indicates that the observable is harmful to the organization. - Suspicious: Indicates that the observable might be harmful to the organization. - Clean: Indicates that the observable is not harmful to the organization. - Unknown: Indicates that we are yet to determine the observable's finding. - Default value: Unknown. For more information, see Threat Lookup Finding Calculators.

Note: After an upgrade, existing observables are marked Malicious.

Operator

This field appears only when the Is composition check box is selected. Depending on your setting in this field, the observables and their children are considered when deciding whether an associated indicator is present. Set this field to AND if all the child observables must be present for an associated indicator to be considered present.

Set it to OR if any of the child observables are present for an associated indicator to be considered present.

Must not be presentThis field displays only after the observable record has been saved.If selected, this field signifies that the absence of the observable is the potential issue \(for example, a missing registry key\).
LocationUsing the settings in two properties and a script include definition, you can load Load more IoC data in this field.
NotesEnter any additional notes about the observable.
  1. Right-click in the form header and click Save.

    You can now click any of the following related lists to view additional information.

    Related ListDescription
    Related IndicatorsLists indicators that have been identified by the threat source.
    Associated TasksLists changes associated with the observable.
    Child ObservablesLists related observables that have been identified by the threat source.
    Matching Resources for IPIf the observable is an IP address, this list shows any resources (configuration items) that have a matching IP address.
    Observable SourcesLists the sources of this observable, along with the confidence level of the source.
    Security AnnotationsLists security annotations added to this observable.
  2. Returning to the security incident the following information is available.

    Note: When you add an observable to the security incident, the system checks for any other configuration items or users associated with it. The Related Configuration Items and Related Users related list tabs are updated accordingly.

ColumnDefinition
ObservableThe value \(for example, IP address or hash\) associated with the observable.
Observable TypeThe specific type of observable.
Context

Selected by the user. Choices are:- IP - Source or Destination

Note: If Threat Intelligence and Palo Alto Networks - Firewall are activated, changing or adding a value to this field causes the Get Log Data Flow Security Operations Palo Alto Networks - Get Log Data workflow to execute. The workflow retrieves enriched threat log data from the firewall and attaches it to the security incident. The information is also parsed and displayed in the Firewall Logs section under the Enrichment Data tab.

  • URL - Referrer

Note: When the user clicks a link in a phishing email, a referrer is the URL of the final jump before the malware URL is accessed.

Incident CountThe number of incidents that this observable appears in. This value is automatically updated when the observable is added to another incident manually or through a workflow.
UpdatedData and time the list was last updated.
**Note:** If the Threat Intelligence plugin is installed, you can also view the observable in the **Observables** list in the **IoC Repository**.

Related topics

Edit a security incident observable list

Add multiple security incident observables