Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Define object-indicator relationships

Define relationships between the indicator object and other SDOs.

Before you begin

Role required: sn_sec_tisc.analyst

Procedure

  1. Navigate to Workspaces > Threat Intelligence Security Center.

  2. Click on Threat Intel Library icon on the workspace.

  3. Go to Relationships > Object-Indicator.

  4. Click New.

  5. Complete the fields in the form as appropriate.

FieldDescription
IndicatorSelect and define the indicator.
ObjectSelect and define the object.
Relationship TypeA description that provides more details and context about the relationship type. Define the relationship direction whether it is direct or inverse. - Inverse - This is the type of relationship between the observable and object. - Direct - This is the type of relationship between the object and observable.
Start TimeSpecifies the time when the relationship is created.
Stop TimeSpecifies the time when the relationship is stopped or removed.
DescriptionA brief description about the object relationships.
  1. Click Submit.

Parent Topic:Relationships Objects