Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Define object-observable relationships

Define relationships between SDOs and the observable object (SCO).

Before you begin

Role required: sn_sec_tisc.analyst

Procedure

  1. Navigate to Workspaces > Threat Intelligence Security Center.

  2. Click on Threat Intel Library icon on the workspace.

  3. Go to Relationships > Object-Observable.

  4. Click New.

  5. Complete the fields in the form as appropriate.

FieldDescription
ObservableSelect and define the observable.
ObjectSelect and define the object.
Relationship TypeA description that provides more details and context about the relationship type.Define the relationship direction whether it is direct or inverse. - Inverse - This is the type of relationship between the observable and object. - Direct - This is the type of relationship between the object and observable.
Start TimeSpecifies the time when the relationship is created.
Stop TimeSpecifies the time when the relationship is stopped or removed.
DescriptionA brief description about the object relationships.
  1. Click Submit.

Parent Topic:Relationships Objects