Get started with Sighting Search Configurations
Sighting Search Configurations define how threat intelligence data is searched and matched against your environment. Configure these settings to customize threat detection and improve security monitoring accuracy.
The Elasticsearch and Splunk Sighting Search integrations enrich observables with sighting information from your log data. Elasticsearch searches logs to add relevant sightings directly to observables, while Splunk searches, monitors, and analyzes machine-generated data across Security Operations. Download the Splunk Sighting Search integration from the ServiceNow Store.
- Configure and enable Elasticsearch integration
Elasticsearch is a distributed, RESTful search and analytics engine that easily integrates with Security Operations. - Configure and enable Splunk integration
Configure the Splunk Enrichment integration to automatically search your logs and add relevant sighting information to threat intelligence data.
Parent Topic:Configure Sighting Search