Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Security Analyst Workspace properties

These system properties are used to configure the Security Analyst Workspace.

There are two types of properties:

  • Properties that are typically not modified like sys_ids and product keys.
  • Properties that are modified as required like long poll intervals and user interface configurations.

Note: The Security Analyst Workspace properties are located at this location: Security Incident > Analyst Workspace Setup > Analyst Workspace Properties.

Property NameDescription
Fields that are hidden by default in the response task banner. sn\_app\_secops\_ui.form.excluded\_fields.response\_task
  • Type: string
  • Default value:
  • number
  • short description
  • comments
  • work_notes
  • comments_and_work_notes
  • work_notes_list
  • automation_activity
Fields that are hidden by default in the incident banner. sn\_app\_secops\_ui.form.excluded\_fields.incident
  • Type: string
  • Default value:
  • number
  • short description
  • comments
  • work_notes
  • comments_and_work_notes
  • work_notes_list
  • automation_activity
  • security_tags
Background color style is applied to the fields listed here. sn\_app\_secops\_ui.form.color\_coded\_fields
  • Type: string
  • Default value:
  • business criticality
  • impact
  • priority
  • risk_score
  • severity
If true, tables extended from the sn\_si\_task base response task table, will also have access to email templates created for the base response task table. sn\_app\_secops\_ui.extend.base.response\_task.email\_templates
  • Type: true \| false
  • Default value: true
Sets the width of each summary field in each response task banner. sn\_app\_secops\_ui.task\_summary.single\_summary.width.response\_task
  • Type: integer
  • Default value: 10
Sets the width of each summary field in each incident banner. sn\_app\_secops\_ui.task\_summary.single\_summary.width.incident
  • Type: integer
  • Default value: 15
Sets a limit on the number of summary fields allowed in the incident banner. sn\_app\_secops\_ui.task\_summary.single\_summary.limit.incident
  • Type: integer
  • Default value: 12
Sets a limit on the number of summary fields allowed in the response task banner. sn\_app\_secops\_ui.task\_summary.single\_summary.limit.response\_task
  • Type: integer
  • Default value: 12
Sets a limit on the number of summary fields allowed in the first line of the incident banner. sn\_app\_secops\_ui.task\_summary.single\_summary.limit.incident.first\_line
  • Type: integer
  • Default value: 3
Comma separated list of fields that may have user photos. sn\_app\_secops\_ui.form.user\_fields
  • Type: string
  • Default value:
  • affected_user
  • caller
  • sys_updated_by
  • sys_created_by
  • opened_by
  • closed_by
  • submitted_by
Sets the width of each summary field in each incident peek view. sn\_app\_secops\_ui.task\_summary.single\_summary.width.incident\_peek
  • Type: integer
  • Default value: 13.5
Comma separated list of fields that display time. sn\_app\_secops\_ui.form.time\_fields
  • Type: string
  • Default value:
  • opened_at
  • sys_created_on
  • sys_updated_on
Controls the frequency \(in milliseconds\) at which the sighting search results are refreshed. sn\_app\_secops\_ui.poller\_interval.search\_action
  • Type: integer
  • Default value: 30000

Minimum: 15000

Controls the frequency \(in milliseconds\) at which the count or query data is refreshed. sn\_app\_secops\_ui.poller\_interval.related\_list
  • Type: integer
  • Default value: 30000

Minimum: 15000

Controls the frequency \(in milliseconds\) at which the result data is refreshed \(for the playbook\). sn\_app\_secops\_ui.poller\_interval.playbook\_tasks
  • Type: integer
  • Default value: 30000

Minimum: 15000

ID for the Security Operations Integration - Isolate Host workflow. sn\_app\_secops\_ui.workflow.id.isolate\_host
  • Type: string
  • Default value: d72041f1ff203200c68c84648e94fa5e
ID for the Security Operations Integration -Watchlist workflow. sn\_app\_secops\_ui.workflow.id.publish\_to\_watchlist
  • Type: string
  • Default value: 35800c0eff343200c68c84648e94fa85
ID for the Security Operations Integration - Block Request workflow. sn\_app\_secops\_ui.workflow.id.block\_request
  • Type: string
  • Default value: 11a6a5270b9032008f9108e3c5673a24
ID for the sn\_si\_analyst user role. sn\_app\_secops\_ui.roles.id.sn\_si.write
  • Type: string
  • Default value: 66878663ff123100158bffffffffff8d
ID for the sn\_si\_read user role. sn\_app\_secops\_ui.roles.id.sn\_si.read
  • Type: string
  • Default value: ae878663ff123100158bffffffffff8e
ID for the sn\_si\_admin user role. sn\_app\_secops\_ui.roles.id.sn\_si.admin
  • Type: string
  • Default value: 22878663ff123100158bffffffffff8d
ID for the Microsoft Exchange - Perform Email Search and Delete workflow. sn\_app\_secops\_ui.email.phishing.manual.workflow
  • Type: string
  • Default value: ed9f289cc310220031fbdccdf3d3aeb4
ID for the Add to Deny list custom action under the Explore tab in the Security Analyst Workspace. sn\_app\_secops\_ui.explore.action.direct.id.deny\_list
  • Type: string
  • Default value: DENY_e9bd0ac50b632200263a089b37673a0b
ID for the Add to Allow list custom action under the Explore tab in the Security Analyst Workspace sn\_app\_secops\_ui.explore.action.direct.id.allow\_list
  • Type: string
  • Default value: ALLOWLIST_e9bd0ac50b632200263a089b37673a0b
ID for the Run Threat Lookup UI Action. sn\_app\_secops\_ui.explore.action.id.run\_threat\_lookup
  • Type: string
  • Default value: da5ff4420b540300263a089b37673ae7
ID for the Threat Lookup integration capability. sn\_app\_secops\_ui.explore.capability.id.threat\_lookup
  • Type: string
  • Default value: 39344d4f0b273200263a089b37673ab1
ID for the Observable Enrichment custom action under the Explore tab in the Security Analyst Workspace. sn\_app\_secops\_ui.explore.action.id.observable\_enrichment
  • Type: string
  • Default value: OBS_ENRICHMENT_54e2f5d60b5003009f66e94685673a1e
ID for the Enrich Observable integration capability. sn\_app\_secops\_ui.explore.capability.id.observable\_enrichment
  • Type: string
  • Default value: 9ad183640b1003009f66e94685673af4
ID for the Publish to Watchlist UI Action. sn\_app\_secops\_ui.explore.action.id.publish\_to\_watchlist
  • Type: string
  • Default value: 8ee94002ff743200c68c84648e94faf9
ID for the Block Request UI Action. sn\_app\_secops\_ui.explore.action.id.block\_request
  • Type: string
  • Default value: 7158f6e40b2032008f9108e3c5673adf
ID for the Run Sightings Search UI Action. sn\_app\_secops\_ui.explore.action.id.sightings\_search
  • Type: string
  • Default value: 43f91a6f0b032200b97c67d985673a2c
ID for the Create Child Security Incident UI Action. sn\_app\_secops\_ui.explore.action.id.create\_child\_incident
  • Type: string
  • Default value: 5a6882645363530099d5ddeeff7b1272
ID for the Add Security Annotation UI Action. sn\_app\_secops\_ui.explore.action.id.add\_security\_annotation
  • Type: string
  • Default value: 1e3a3e723b5332005a9149a4d2efc4eb
ID for the CI Enrichment Custom Action under the Explore tab in the Security Analyst Workspace. sn\_app\_secops\_ui.explore.action.id.ci\_enrichment
  • Type: string
  • Default value: CI_ENRICHMENT_54e2f5d60b5003009f66e94685673a1e
ID for the Isolate Host UI Action. sn\_app\_secops\_ui.explore.action.id.isolate\_host
  • Type: string
  • Default value: d6244e0aff203200c68c84648e94fad3
ID for the Add Multiple Observables UI Action. sn\_app\_secops\_ui.explore.action.id.multiple\_observable
  • Type: string
  • Default value:138de478d78322007a6de294de6103aa
Product key for ag-Grid-Enterprise. sn\_app\_secops\_ui.ag-grid-license
  • Type: string
  • Default value:ServiceNow_ServiceNow_5Devs2_August_2018__MTUzMzE2NDQwMDAwMA==cedabe1c76ccf28f23aec398ec32997d