Security Operations - QRadar Sightings Search workflow Security Operations - QRadar Sightings Search workflow is the implementation for the IBM QRadar integration launched by the Security Operations Integration - Sightings Search workflow. Before you beginRole required: sn_si_analyst About this task Workflow process activities include: Execution Tracking - Begin activity Collect QRadar Configurations activity Capability Execution Tracking - Failure activity Checks to see if the MID Server is running. QRadar Event QueryActivity activity Persist Observable Sightings activity - returns search results in an array. Capability Execution Tracking - Complete activity Execution Tracking - Begin activityThe Execution Tracking - Begin workflow activity starts the auditing process for a Security Operations Integration workflow that operates on observables. Collect QRadar Configurations activityThe Collect QRadar Configurations workflow activity gathers configuration information to use in the workflow.QRadar Event QueryActivity activityThe QRadar Event Query workflow activity searches the QRadar event logs for malicious indicators.Persist Observable Sightings activityThe Persistent Observable Sightings workflow activity retrieves observables from the third-party integration.