Skip to content
Release: Australia · Updated: 2026-04-22 · Official documentation · View source

Configure Sighting Search

Configure sighting search integration to search your organization logs for one or more observables to determine how many times each observable appears, within a specified date range or number of days.

Before you begin

Important: The enrichment integrations appears only if at least one enrichment integration is installed and active.

The Threat Intelligence Security Center supports Sightings Search for the following integrations only:

  • Splunk Search
  • Elasticsearch

Role required: sn_sec_tisc.admin

Note: The Sightings Search section lists integrations of the Sightings Search type. Each configured integration appears as a card, which you can enable or disable.

Procedure

  1. Navigate to Workspaces > Threat Intelligence Security Center.

  2. Select the Integrations icon.

Image omitted: enrich-sighting-section.png
Sighting Search page showing three enabled enrichment integration cards: two Splunk integrations and one Elasticsearch integration, each with a last-modified timestamp and View button.
  1. Select the Configure new enrichment action.

    A dialog displays the available integrations. You must select the integration that you want to configure.

  2. Select an integration from the list of available integrations.

    The Configure new enrichment page for the selected integration opens. This page is pre filled with details of the selected integration by default. For example, Splunk integration.

Image omitted: enrich-sighting-config.png
Create Enrichment Integration form with Vendor Name set to Splunk, Integration Type set to Sighting Search, and the Integration Configuration section visible.
  1. On the Create Integration form, fill the fields.
FieldDescription
Enrichment Integration
NameName of the new enrichment integration. For example, `Splunk-1`.
Vendor NameName of the vendor.Note: The details of the selected vendor are pre-filled by default. For example, Splunk.
Integration TypeType of the selected integration.Note: This field is automatically set to Sighting Search and prefilled by default.
DescriptionUnique description of the new enrichment integration.
Image omitted: enrich-sighting-splunk.png
Create Enrichment Integration form with Vendor Name set to Splunk and Integration Type set to Sighting Search.
  1. In the Integration Configuration section, configure the integration details based on your requirements.

    The Integration Configuration section includes configuration details such as the API key, API Client ID or Secret, username, and password. The required details vary depending on the integration.

  2. Select Save to create the enrichment integration configuration.

    The provided details are validated and the enrichment integration is inactive by default.

  3. Select Save as Draft to save the enrichment configuration as inactive.

    You can activate it later.

    Note: If you're unsure about the configuration details, select Save as Draft. After you obtain the required details, open the draft and enter the remaining information, and select Save to activate the integration.

  4. Select Enable to enable the enrichment integration.

    The enrichment integration is enabled. You can also enable a particular enrichment integration from the Actions on the integration tile on the Catalog.

  5. Create Sighting Search queries
    Sighting search configurations define queries that search for observables across your security environment during investigations. Configure these queries to determine how often specific indicators appear in your data sources.

  6. Using Sighting Search parameters
    Configure advanced search parameters to create complex queries with logic operators and other features supported by your log store. Use these parameters when basic search criteria are insufficient for your investigation needs.
  7. Get started with Sighting Search Configurations
    Sighting Search Configurations define how threat intelligence data is searched and matched against your environment. Configure these settings to customize threat detection and improve security monitoring accuracy.

Parent Topic:TISC Enrichment integrations