Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Deleting threat intelligence library records

Delete threat intelligence library records such as observables, indicators, and objects.

Before you begin

Role required: sn_sec_tisc.analyst

The following example procedure explains how to delete an observable record. You can use the same procedure to delete indicators or objects as well.

Procedure

  1. Navigate to Workspaces > Threat Intelligence Security Center > Threat Intel Library > Observables > All Observables.

  2. Open any observable record.

  3. Select Delete to delete the aggregated record.

    When you select this action, then it will remove all the related records, except the original source data, and trigger reaggregation.

    A confirmation message will appear to verify that you want to delete the aggregated record. If you also want to delete the source records and prevent re aggregation, select the Delete Source Records check box. This action will remove all the associated source records.

Image omitted: tisc-delete-library-record.png
Delete library records
  1. Select Delete.

    The record will be deleted from threat intelligence library.

What to do next

Refer to the section Define an Observable to create a record.

Parent Topic:Threat Intel Library

Related topics

TISC Data Model

TISC Library Objects form view

TISC Library Repository

Access Vulnerability Downstream actions

Export intelligence data

Confirm Potential Relationships from Related Records

Automated Correlation