Create and configure a profile for sightings search with the FireEye Integration
-
- UpdatedJan 30, 2025
- 2 minutes to read
- Yokohama
- Security Incident Response integrations
Configure the sightings search profile using the following procedure.
Before you begin
Role required: NowPlatform Security incident administrator (sn_si.admin)
Whenever a source is created, individual sightings search configurations for five types (File,
IPs(v4), MD5, SHA1 and SHA256) will be created and inactive by default. You should
make it active before using Sighting Search. Each Observable type is having
different search query to retrieve sightings. We would be initiating a different
search for each observable type. Multiple observables search for a sighting search
is not possible in FireEye as it would perform an AND operation on the observables
and the result might be inaccurate.
Note: For Sightings search only five active
searches can be present at once. Remaining will be queued and will start after
the completion of any one of the ongoing sightings.
If you want to create a new sightings search profile, follow the steps below to create one:
Procedure